Will Manifold experience a serious security breach that compromises at least one user's personal data by the end of 2024?
70
778
แน€1.3K
resolved Sep 12
Resolved
YES

Could include email addresses, credit card numbers, etc.

A single user choosing a bad password and having their data stolen doesn't count; it must be Manifold's system at fault.

Breaches that occurred prior to this market's creation do not count.

Get แน€200 play money

๐Ÿ… Top traders

#NameTotal profit
1แน€3,011
2แน€410
3แน€156
4แน€128
5แน€66
Sort by:
predicted NO

Mira has submitted https://manifold.markets/Mira/will-manifold-leak-everyones-privat-b91cb81a49c8 as evidence that this should resolve YES. Any objections?

bought แน€100 of YES

Oh duh, yeah this market was made ages ago I forgot it counted stuff that already happened. That seems correct to me.

sold แน€53 of NO

called it https://manifold.markets/IsaacKing/will-manifold-experience-a-serious

i think it's debatable, but lean yes? I think the attempt to pretend that my suggestion wasn't what they meant, laundered behind a joke, wasn't ideal conduct.

predicted NO

@IsaacKing Was it actually โ€žpersonal dataโ€?

yes

predicted NO

@IsaacKing just to make sure I'm understanding what happened here. This market was made a long time ago, information leaked in mid August, and then we only realized it applied to this market today?

And to be extra clear, nothing new has leaked since the linked market in August?

bought แน€5,000 of YES

@zzlk I have not been informed of any new leaks, no.

(I was absent from the platform for ~4 months, so I was unaware of the earlier leaks until Mira told me.)

@IsaacKing wish that this wasnt sufficient for a resolution, I was really looking forward to what'd be presented next by Mira

bought แน€100 of NO

The question is, how long does Mira want to wait before revealing the breach in order try to get more mana?

bought แน€50 of NO

Do people know something I donโ€™t?

predicted NO

@esusatyo I would have substantially more profit if I followed these two simple rules:

  1. Donโ€™t bet against Messi

  2. Donโ€™t bet against @Mira

sold แน€35 of NO

@Charlie Youโ€™re right

bought แน€5 of NO

IMO it's way too high now. Credit card numbers aren't even stored in Manifold's DB, they use Stripe. So the only option is to leak e-mail addresses? I can't think of a use case in which a bug could cause it, since users are identified by id and user name.

bought แน€0 of YES

e-mail addresses or "etc."

bought แน€1,000 of YES

Would you say the "security breach" is more important, or the "leak of people's personal information"? Is there a minimum "difficulty level" required?

i.e. suppose Manifold puts up an endpoint "/v0/credit-card-number" or starts putting email addresses in the API responses. Would that resolve this positively even though it was intentional and requires no 'hacking'?

Or if they unintentionally include email addresses in the output, patch it, but it's not like a targeted attack from a hacker - they just were careless and gave it out? Maybe it wouldn't be "serious" just because it's so easy to do.

@Mira should we be worried

predicted YES

@Mira a security breach does not have to be initiated or even exploited by someone external to be a serious breach imho.

Say that a backup of the database containing emails was inadvertently made public, and someone in the team figures it out and takes it offline before anyone downloads it, I'd still count that as a serious breach.

predicted NO

@Mira That all sounds like it would count. If they unintentionally expose user data that's still a "breach", even if it's not a "hack". If they do it intentionally... that would be weird, but I guess it still counts.

bought แน€40 of NO

Maybe (probably not) you're talking about unlisting private markets and revealing some of them? I think it's debatable if that's a security breach.

bought แน€0 of YES

@jacksonpolack I mean it's written in Javascript right? Even if I don't have anything now, what are the chances that it goes a whole year without getting hacked?

bought แน€100 of YES

Semiconductor market currently redirects to a different website.

predicted YES
boughtแน€250YES

@Mira ๐Ÿค”

q: would it count if someone who is not an employee at Manifold finds and reports a vuln that would have classified as a breach per rules if being exploited, but instead of being exploited it gets fixed?

predicted NO

@NikitaSkovoroda No, I don't think that should count.

@IsaacKing Perhaps I should just make another market )

Comment hidden