Live data from Hacker News

The 111M Record Pemiblanc Credential Stuffing List

troyhunt.com

21–30 of 73 posts

Re: The 111M Record Pemiblanc Credential Stuffing List

#21

Earlier quoted context omitted.

A variation on the password algorithm: Generate half of your password by using the algorithm. Create the other half, one per site, using a random algorithm, and write it on a piece of paper (if the site has stupid "security" requirements for the password, you can usually fit these into your random string). To regenerate your passwords, an adversary would need both to figure out your algorithm and obtain your piece of…

If you're already writing half the password on a piece of paper wouldn't it be safer to generate the whole password randomly and write that down?

Or, you know, use a password manager.

Re: The 111M Record Pemiblanc Credential Stuffing List

#22
post #19
post #8

So in the past I've advocated password algorithms (sometimes called password formulas): https://penguindreams.org/blog/password-algorithms/ I felt like they could bridge the gap between a regular person who is weary of having to look up every password using a password manager (although a lot of them make it easier with browser plugins and phone apps, but it's still an extra step). However, in light of the recent Gent…

As someone technically literate but doesn't use a password manager: I sign up for a lot of services on one device (home laptop) and then need to use them on another device (work laptop, phone). How does a password manager work for this? I currently have about ~15 different passwords I use. I know which to use based on how long I've been using the service. Why is this strategy ineffective?? At most a hacker could get…

Most password managers provide apps and syncing, and are often integrated into your browser, so everything is a click away. Having to juggle 4 emails, remember which of 5 passwords a site uses, and figure out your exposure in case of a breach seems a lot harder than the above.

Re: The 111M Record Pemiblanc Credential Stuffing List

#23
post #8

So in the past I've advocated password algorithms (sometimes called password formulas): https://penguindreams.org/blog/password-algorithms/ I felt like they could bridge the gap between a regular person who is weary of having to look up every password using a password manager (although a lot of them make it easier with browser plugins and phone apps, but it's still an extra step). However, in light of the recent Gent…

Ew. Friends don't let friends use low-entropy passwords.

"Password Strength" https://www.xkcd.com/936/

Diceware: http://world.std.com/%7Ereinhold/diceware.html "This page offers a better way to create a strong, yet easy to remember passphrase for use with encryption and security programs. Weak passwords and passphrases are one of the most common flaws in computer security. Take a few minutes and learn how to do it right."

Re: The 111M Record Pemiblanc Credential Stuffing List

#24

Earlier quoted context omitted.

A variation on the password algorithm: Generate half of your password by using the algorithm. Create the other half, one per site, using a random algorithm, and write it on a piece of paper (if the site has stupid "security" requirements for the password, you can usually fit these into your random string). To regenerate your passwords, an adversary would need both to figure out your algorithm and obtain your piece of…

If you're already writing half the password on a piece of paper wouldn't it be safer to generate the whole password randomly and write that down?

If only half the password is written down, anyone who obtains that paper without knowing the algorithm only knows half the password!

Re: The 111M Record Pemiblanc Credential Stuffing List

#26
post #13

Where can I download the list? I want to see what password was shared.

He loaded them into this site to check: https://haveibeenpwned.com/ I'm not sure troy shares the lists - for obvious reasons.

His site is basically one big advertisement for 1password now. I would not trust it.

Re: The 111M Record Pemiblanc Credential Stuffing List

#27
post #19
post #8

So in the past I've advocated password algorithms (sometimes called password formulas): https://penguindreams.org/blog/password-algorithms/ I felt like they could bridge the gap between a regular person who is weary of having to look up every password using a password manager (although a lot of them make it easier with browser plugins and phone apps, but it's still an extra step). However, in light of the recent Gent…

As someone technically literate but doesn't use a password manager: I sign up for a lot of services on one device (home laptop) and then need to use them on another device (work laptop, phone). How does a password manager work for this? I currently have about ~15 different passwords I use. I know which to use based on how long I've been using the service. Why is this strategy ineffective?? At most a hacker could get…

I use Google Smartlock, and it functions across all my (android) devices quite well. It does sort of rely on your being all-in on the Google ecosystem. At work we use LastPass, but since I only use it on the desktop in a browser I can't speak to how it works across devices.

Re: The 111M Record Pemiblanc Credential Stuffing List

#28

These data breaches where the source isn't known can be frustrating. As someone who already uses unique passwords for everything, there's not much I can do (change 500+ passwords?). And I can understand Troy's argument[1] for not sharing the leaked password, so that doesn't leave many other options. I guess I'll just start going through my saved passwords and use them to delete all of the old accounts I rarely use, m…

Well, you can see who leaked the password by checking for your password if it’s unique, right?

Re: The 111M Record Pemiblanc Credential Stuffing List

#29
post #27
post #19

Earlier quoted context omitted.

As someone technically literate but doesn't use a password manager: I sign up for a lot of services on one device (home laptop) and then need to use them on another device (work laptop, phone). How does a password manager work for this? I currently have about ~15 different passwords I use. I know which to use based on how long I've been using the service. Why is this strategy ineffective?? At most a hacker could get…

I use Google Smartlock, and it functions across all my (android) devices quite well. It does sort of rely on your being all-in on the Google ecosystem. At work we use LastPass, but since I only use it on the desktop in a browser I can't speak to how it works across devices.

LastPass works for multiple devices, including mobile - you can sync to 1 LastPass account, too.

Re: The 111M Record Pemiblanc Credential Stuffing List

#30
post #13

Earlier quoted context omitted.

He loaded them into this site to check: https://haveibeenpwned.com/ I'm not sure troy shares the lists - for obvious reasons.

His site is basically one big advertisement for 1password now. I would not trust it.

I'm not sure why you're being downvoted when you're exactly right. I have lost a lot of respect for Troy Hunt when he pretty much turned his blog and HIBP into a native advertisement for 1Password; without any disclosure that he is being paid by 1Password.
Post reply on HN