Opera server breach incident
opera.com
opera.com
I would have assumed that if a database was breached, then the bad guys could access the entire user or password hash table? Would 'only some' data mean that they detected a 'SELECT * FROM users' query being run and shut down the connection before it could complete? Is it the database sharding they use which means the entire table is not visible at one time?
I'd be interested to hear more about technique or technologies available to prevent global queries to scrape entire tables once someone has gained access to your database.
I believe in the case of the LinkedIn breach, they said that something like "less than 20% of their user passwords were leaked". I take that to mean that not all rows were exposed, but only some - that's why I am intrigued as to whether the query was shut off mid stream, or the bulk download of exported data was detected and cut off or similar?
In this post for instance, they indicate that attackers got 'sync users’ passwords' while storing only 'encrypted/hashed data'.
Other possibilities: they accessed a partial backup (or prod data used in dev), a caching system, a message broker (Kafka)...
Doing so keeps your db responsive against programmer errors and limits data exfiltration. I've been doing this for the first reason for years.
But opera as a company is long dead for me, all the people behind the old opera have moved on and many of them working on Vivaldi.
EDIT: Hope I haven't offended anyone, I am usually not the judgemental type, couldn't help wondering in this case.
I wasn't aware this came across as desperate for virtual points. I really don't care.