Speech for the “Voice of the World” Yixin group: Today I want to discuss privacy leaks and protection in the information age. Episode 5 of season 2 of Luo Ji Siwei, “To Our Privacy That Will Eventually Disappear,” focused mainly on privacy leaks caused by big-data analysis. Today I will talk about other ways personal privacy is exposed and how to reduce those risks to some extent. There is no privacy in the information age. All privacy is relative; absolute privacy does not exist. I will illustrate this with examples. Some data already available online for tonight’s talk has not been censored, while privacy-related details have been mosaicked. First, let me share some recent news familiar to everyone. I. Recent major incidents
- Gmail password leak On September 11, 2014, nearly 5 million Gmail usernames and passwords were leaked. The information involved users in multiple countries across several Google services, including Gmail and Google Plus. Figure 1.1 shows a statistical breakdown of Gmail passwords; weak passwords such as 123456 and password were not uncommon.

- The Hollywood celebrity photo leak: Between September 1 and October 5, 2014, the Apple iCloud accounts of more than 60 Hollywood actresses were compromised, and many private photos were exposed.
- 20-million hotel registration records leaked: The 1.7G database circulating online contained 33 fields involving personal information. 27 fields were relatively complete, and 14 directly involved personal information, including name, sex, nationality, ethnicity, ID number, birthday, address, postal code, mobile phone, landline, fax, email, company, and dates of stay.
- CSDN plaintext passwords On December 21, 2011, CSDN confirmed that a database containing 6 million records had been leaked. According to reports, a Tencent Weibo user revealed that hackers had publicly posted the CSDN user database online. The leaked CSDN passwords were stored in plaintext without any encryption. Because most CSDN users were programmers, the incident had a major impact.
- GSM text-message interception In mid-October 2014, the Kingsoft Antivirus Security Center simulated a hacker experiment and found that equipment costing less than 100 yuan could intercept text messages from nearby 2G phones, without any contact with the phones. In an office building in Beijing, hackers listened to and collected dozens of messages in just five minutes. All the content could be viewed in plaintext, including private chats between friends, work reports, bank-transfer notices, and group-buying-coupon notifications. They even used a coupon to obtain movie tickets at a cinema.
There are many similar cases, and the harm can be serious. When leaked data is posted online, people may check whether their own passwords were exposed while also seeing large amounts of other people’s information, giving criminals opportunities for telephone fraud, advertising, and more. Company secrets in email can leak as well. Those stories may seem far away, so next I will give examples of information leaks around us. II. Information leaks close to home
- The first category is weak or default passwords on various accounts
As students at HEBUT, we use a website for course registration, checking timetables, and teaching evaluations: the academic affairs system. It seems convenient, but it can also expose students’ personal information because it contains detailed enrollment records and photos. Today I will set aside vulnerabilities in the system itself and focus on how students’ password choices expose personal information. When we entered our first year, the school gave us student IDs, and the default password was the same as the ID. Teaching secretaries in each school division should also have reminded everyone during orientation how to change it. (I saw the slides Wu Fan used to help the counselor give a lecture to new students in the School of Engineering II; the instructions for changing the password were very detailed.) Yet many students still did not change their passwords. I conducted a simple test, randomly selecting 50 students from the School of Information for brute-force logins; 13 had not changed their passwords. As shown in Figure 2.1.1, those circled in red had identical student-ID and password.
These were the students who had not changed their passwords. Some students had changed theirs, but their passwords contained only a few digits. Because the academic affairs system had no CAPTCHA, this left an opening for brute-force attacks. I tried to crack the academic password of a student in our Yixin group; because it had only six digits, finding the correct password would not take long. As shown in Figure 2.1.2,
After trying to log in, as shown in Figure 2.1.3, I could see names, student IDs, majors and classes, home addresses, college entrance-exam scores, ID numbers, and personal photos. Parents’ contact details in particular could give criminals an opportunity to commit fraud. 
- The second category is unintentional leaks
Location information can leak through location features in Weibo, Qzone, and other social apps, often without our realizing it. Unlike location sharing in a Yixin group chat, a Weibo location cannot be changed at will; it displays the real location shown in Weibo. I originally wanted to use Qzone and Weibo to find where some people in our group lived. I searched Hailin’s Qzone for a long time but could not find any posts tagged at home, which showed that she had a relatively strong awareness of privacy. Most of her Weibo posts were sent from school. Of course, she also went out often, so it was easy to see where she had been. I eventually stopped looking. Technical methods can modify a location, however; one noon when I had nothing else to do, I tested it and teleported to New York for a while, as shown in Figure 2.1.
Personal information can leak too. Figure 2.2.1 shows a notice a teacher posted in a group. I added the mosaics later; the notice reminded everyone to beware of fraud, but it also exposed the names and QQ numbers of the School of Engineering secretary and counselor, creating another opportunity for fraud.
For another example, a few days ago Hailin asked Wu Fan and me for our mobile numbers in the Voice of the World QQ group, and I sent them without hesitation. Figure 2.2.2 shows this. More than 400 people in the group now knew my mobile number. No one could determine whether the owners of the numbers were alumni themselves or criminals who had stolen their QQ accounts. 
- The third category is hotel records, Gmail passwords, forum passwords, and other data obtained from database leaks
I tried querying Shaoyang’s QQ-group relationships, as shown in Figure 2.3.1. Although the data was two years old, it still revealed some information. If you knew a QQ number, you could also find the person’s real name, because people usually put their real names in their QQ group-card remarks. Figure 2.3.2 shows Wu Fan’s remarks in various groups.
There are many other ways for information to be obtained, such as phishing websites that imitate a real website’s login page. Students with more online experience can usually identify a phishing site by its domain name, but people who do not know what to look for can easily enter their account and password there. I will not list every other way criminals can obtain information. III. Some suggestions
- Password-setting plans (an engineer’s password)
Set a complex password to prevent brute-force attacks. A password of at least 8 characters, with uppercase and lowercase letters, punctuation, and special symbols, is difficult to crack by brute force. Figure 3.1 shows a strong password set by an engineer in the CSDN password leak: it uses lines of poetry to form a very complex password. Engineers are certainly creative.
If a network service provider’s database is leaked and passwords are stored in plaintext, even the most complex password can be obtained. So what should we do? I offer two password plans for reference only. One plan is to use passwords for different risk levels: an extremely confidential password for payments, as complex as possible and told to no one; a confidential password for social apps such as QQ that contain a lot of personal information, also told to no one; and a secret password for casual forum or Tieba posting, where even if someone learns it, it would not cause losses or expose much personal information. Change these passwords regularly. The other plan is to use a different password for every website, with an encryption algorithm known only to you. For example, use a few shared digits, 123456, then set the QQ password to QQ12345 and the Weibo password to WB123456. Of course, these examples are too simple and are only meant to illustrate the idea. A more complex algorithm could be used. For example, shift keys on the keyboard: moving Q two keys to the right gives E, so one password could be EE123456 and a Tieba password could be UM123456. This is only an example. The two plans can also be used together.
- We should also improve our awareness of privacy protection and pay attention to our online behavior. For example, do not leave your own or other people’s information online or casually upload photos of identity documents. If you must upload one, add a watermark such as “For use by a certain person, month, or company for a specific matter only.” Do not casually connect to wireless networks in public places. Mobile data is much safer than public Wi-Fi, even if it costs a little more in data charges.
- After hearing so much tonight, do you feel that the internet is unsafe and that you should stop using it? There is no need to become paranoid. Everyone only needs to raise their security awareness and continue using the internet normally.
Recommended videos:
1. Daoge (Wu Hanqing), chief designer of Alibaba security architecture – Hacking for Fun
2. GSM text-message interception demonstration
Link: http://yxs.im/Ogzh60 Password: mzn5 (download link for tonight’s talk). Thanks to Shaoyang for compiling the recording.