Live data from Hacker News

The 111M Record Pemiblanc Credential Stuffing List

troyhunt.com

61–70 of 73 posts

Re: The 111M Record Pemiblanc Credential Stuffing List

#61
post #24

Earlier quoted context omitted.

If you're already writing half the password on a piece of paper wouldn't it be safer to generate the whole password randomly and write that down?

If only half the password is written down, anyone who obtains that paper without knowing the algorithm only knows half the password!

Oh, that's right, thanks!

Re: The 111M Record Pemiblanc Credential Stuffing List

#62
post #54

These data breaches where the source isn't known can be frustrating. As someone who already uses unique passwords for everything, there's not much I can do (change 500+ passwords?). And I can understand Troy's argument[1] for not sharing the leaked password, so that doesn't leave many other options. I guess I'll just start going through my saved passwords and use them to delete all of the old accounts I rarely use, m…

I really don't think HIBP should even be publishing or notifying people about these. It's almost always existing breaches just merged together in a different way. If I went and grabbed the raw torrents and combined them in various ways I could make hundreds of different "credential stuffing" lists. Would HIBP list and notify people about all of them?

This post doesn’t mention it, but on past credential stuffing lists that got loaded, Troy mentioned how many were new to the HIBP dataset. I’d assume that there were enough new emails on here to make it worth loading.

Re: The 111M Record Pemiblanc Credential Stuffing List

#63
post #62
post #54

Earlier quoted context omitted.

I really don't think HIBP should even be publishing or notifying people about these. It's almost always existing breaches just merged together in a different way. If I went and grabbed the raw torrents and combined them in various ways I could make hundreds of different "credential stuffing" lists. Would HIBP list and notify people about all of them?

This post doesn’t mention it, but on past credential stuffing lists that got loaded, Troy mentioned how many were new to the HIBP dataset. I’d assume that there were enough new emails on here to make it worth loading.

Post does mention it.

Re: The 111M Record Pemiblanc Credential Stuffing List

#64
post #51

Earlier quoted context omitted.

Where do you see "IIIm"?

In the title right here on HN, it says 111M. Guess the HN font doesn't clearly distinguish between 1 and I clearly enough.

It's even worse on the site, they use https://fonts.google.com/specimen/Vollkorn

Re: The 111M Record Pemiblanc Credential Stuffing List

#65

Earlier quoted context omitted.

A variation on the password algorithm: Generate half of your password by using the algorithm. Create the other half, one per site, using a random algorithm, and write it on a piece of paper (if the site has stupid "security" requirements for the password, you can usually fit these into your random string). To regenerate your passwords, an adversary would need both to figure out your algorithm and obtain your piece of…

If you're already writing half the password on a piece of paper wouldn't it be safer to generate the whole password randomly and write that down?

[deleted]

Re: The 111M Record Pemiblanc Credential Stuffing List

#66
post #27
post #19

Earlier quoted context omitted.

As someone technically literate but doesn't use a password manager: I sign up for a lot of services on one device (home laptop) and then need to use them on another device (work laptop, phone). How does a password manager work for this? I currently have about ~15 different passwords I use. I know which to use based on how long I've been using the service. Why is this strategy ineffective?? At most a hacker could get…

I use Google Smartlock, and it functions across all my (android) devices quite well. It does sort of rely on your being all-in on the Google ecosystem. At work we use LastPass, but since I only use it on the desktop in a browser I can't speak to how it works across devices.

Does smartlock work with native mobile apps (which may or may not use magic webviee for auth), or is there a way to manually transfer password to log into an app?

Re: The 111M Record Pemiblanc Credential Stuffing List

#67

Earlier quoted context omitted.

His site is basically one big advertisement for 1password now. I would not trust it.

What do you distrust? Do you believe he's lying about the existence of certain breaches? Returning false results for whether a password is compromised? Be specific: what untrustworthy things do you suspect him of?

Since his website is now an advertisement, it's wise to take everything he says with skepticism.. is he pushing the product, or is he providing good advice? What's his motivation for helping users when his main focus is on pushing ads?

As others have pointed out in response to me, he's incredibly dishonest in claiming that his website is funded by him on one page, but clearly he's being paid by a company selling something. He injects ads into email notifications without identifying them as such.

If someone is acting untrustworthy 50% of the time, would you still trust them 100% of the time?

Re: The 111M Record Pemiblanc Credential Stuffing List

#68
post #62
post #54

Earlier quoted context omitted.

I really don't think HIBP should even be publishing or notifying people about these. It's almost always existing breaches just merged together in a different way. If I went and grabbed the raw torrents and combined them in various ways I could make hundreds of different "credential stuffing" lists. Would HIBP list and notify people about all of them?

This post doesn’t mention it, but on past credential stuffing lists that got loaded, Troy mentioned how many were new to the HIBP dataset. I’d assume that there were enough new emails on here to make it worth loading.

94% of the email addresses were already in the database according to the Twitter account. 6% still represents many millions in this case, but perhaps it's unnecessary to notify the ones already known.

Re: The 111M Record Pemiblanc Credential Stuffing List

#69

Earlier quoted context omitted.

What do you distrust? Do you believe he's lying about the existence of certain breaches? Returning false results for whether a password is compromised? Be specific: what untrustworthy things do you suspect him of?

Since his website is now an advertisement, it's wise to take everything he says with skepticism.. is he pushing the product, or is he providing good advice? What's his motivation for helping users when his main focus is on pushing ads? As others have pointed out in response to me, he's incredibly dishonest in claiming that his website is funded by him on one page, but clearly he's being paid by a company selling some…

So, what untrustworthy things do you suspect him of?

FUD is not useful.

Re: The 111M Record Pemiblanc Credential Stuffing List

#70
post #32

Is anyone else annoyed by the native advertising for 1Password there, without any disclosures that they are affiliate links? I've lost pretty much all of my respect for Troy Hunt as he went from maintaining a useful service to just being another ad for 1Password.

His website has always read as thinly-veiled content marketing for Cloudflare and Azure. If you can look past that at the actual informational content, and disregard the specific products mentioned, it's worth reading.
Post reply on HN