Settings

Theme

Epic Games hit by 189GB hack, including login and payment info

rockpapershotgun.com

25 points by kuter 2 years ago · 26 comments

Reader

s_dev 2 years ago

I've seen this screenshot doing the rounds but the Irish Dept. of Foreign Affairs has confirmed they've seen no evidence of a breach. Not sure how common it is but perhaps just a bluff to get some Bitcoin?

  • TehCorwiz 2 years ago

    7GB fits neatly on a thumb drive. Could just be a lost device.

    • s_dev 2 years ago

      That would still constitue a breach. Demonstrating a breach means showing info they should absolutley not have access to.

      That said such Irish systems are very imperfect e.g. low wages for IT staff and there was breach/attack of the countries hospitals systems during Covid however the gov acknowledged the attach at the time. So very much possible.

      I'd need to see more evidence before I'd take this claim seriously though.

j45 2 years ago

Wow.

It almost seems mandatory to use different purchasing emails to limit fall out, and a credit card layer in between like Apple/Google pay or plastiq.

  • unshavedyak 2 years ago

    For almost all my signups these days i use FastMail's email alias feature (built in support in 1Pass now too). I adore it.

    The moment someone comes up with that for CCs with no real downside i'm signing up for them too.

    • WorldMaker 2 years ago

      Advanced Fraud Protection on the Apple Card for the CC number you type into websites changes the CVC ("three digit security code") randomly at regular intervals (I think it is at least weekly?). Also that CC number is "virtual" in that it is different than the CC number Apple Pay uses in NFC transactions and if you have the physical card different from the CC number in the magnetic stripe and different from the CC number in the EMV chip for EMV transactions. (You can't even get a CVC for any of those other numbers, so can't type them into random websites.) The entire virtual, typable CC number can also be rotated to a new CC number manually with mostly just a "button press".

      Some other high end cards have also been learning from Apple Card here and moving to virtual numbers.

      So far, I've seen no real downside to Apple's approach to virtual numbers and the Advanced Fraud Protection CVC rotation (which just starts to feel like a 2FA TOTP for card purchases online the way you check for the latest value after Face ID check from the app every time), and it was definitely one of the factors why I wound up signing up for Apple Card in the first place. Hopefully more of the low end cards and mainstream banks pick up the added protections, too.

      • giancarlostoro 2 years ago

        Also Apple offers the privacy emails as well, though I dont recall if thats via Apple One or whatever that subscription is called.

        • j45 2 years ago

          As much as I prefer Android because it doesn' take 32 taps and swipes to do each thing compared to iPhone, the integration on the Apple side for things like these are what's keeping iPhone in my life.

          I once saw a phone case that let you carry an android phone and iphone back to back. Today maybe it's more possible with remote access or an emulator.

    • stavros 2 years ago

      privacy.com is that for CCs.

  • xyst 2 years ago

    My card generates a new CVV every so often so this is painless.

    iCloud makes it stupid simple to generate email addresses for individual services.

    I do want to migrate away from Apple but for now this “just works”

    • johnny22 2 years ago

      fastmail has masked email and I use that pretty regularly which can do the same thing. It also apparently integrates well with existing password managers like 1password and bitwarden. I haven't used that feature myself, but maybe it would work well enough for you.

      • j45 2 years ago

        Both of these options are usable for the many and not the few.

        Solutions will still require some level of buy in/committment to a platform for most users.

  • greenavocado 2 years ago

    I have 800+ accounts managed with a password manager

1970-01-01 2 years ago

Login and payment info tells me this hack is not likely. Maybe a few accounts were sprayed.

croes 2 years ago

The hack was fake

https://news.ycombinator.com/item?id=39586495

acheron 2 years ago

Uh oh, do they have my payment info from when I bought Castle of the Winds?

  • Kluggy 2 years ago

    What a blast from the past. That used to be my favorite game growing up. I wish it would run on modern machines semi-well.

mvdtnz 2 years ago

This website keeps making the claim that it's a ransomware attack, but neither the original tweet nor Epic's response seem to back that up. Looks like a run of the mill data exfiltration to me.

Also this website has the most insane cookie consent flow I've seen yet. Shameful.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection