Live data from Hacker News

The 111M Record Pemiblanc Credential Stuffing List

troyhunt.com

71–73 of 73 posts

Re: The 111M Record Pemiblanc Credential Stuffing List

#71

Earlier quoted context omitted.

If you're already writing half the password on a piece of paper wouldn't it be safer to generate the whole password randomly and write that down?

Or, you know, use a password manager.

Which password manager is the most secure / robust / potentially long lasting company out of: LastPass, 1Password, Dashlane, Keeper (or others?)?

Re: The 111M Record Pemiblanc Credential Stuffing List

#72
post #41

Earlier quoted context omitted.

Did you try to find attackers in the set of unconspicious UAs? If you did not try hard to look for more skilled adversaries, expect some to be hiding from your analysis. Once you don't see anything in a large range of skill/sophistication, you can assume there to be no adversaries that don't have the ability to pull a Stuxnet off. And if you need to guard against those, and have the ressources to do so, you already k…

Agreed, based on other thresholds and alerts, we certainly saw some more advanced actors - using in-country home broadband lines to conduct the attacks. This made tracking and blocking them much harder, as there was a risk of blocking genuine customers who simply didn’t conform to our idea of ‘normal’. We ended up finding another way to fingerprint them, but thank you for calling that out, as you are entirely right t…

I hope you have more than one distinct way to identify these more sophisticated attacks, as you would want to be able to ensure there are no others that are only a few steps better than them.

As said, you need to vet a range of sophistication above the most sophisticated example you actually encountered, to assume there are no others that you could reasonably detect with the techniques you could deploy. Always make sure to know you'd see anyone who is only one level better than the best you encountered, where the size of such a level should be estimated from the density you see in the distribution of attacks.

You are also good if you don't automate defense with the best detection you have, so that you prevent an attacker from automatically judging the quality of your detection capabilities with you then believing the attacker got stopped when he just deployed a technique you can no longer see.

I.e., make sure you don't alert an attacker that you can still see him when you are just barely still able to do so, as you would not want him to up his camouflage to the point where you won't see him anymore.

Re: The 111M Record Pemiblanc Credential Stuffing List

#73

Earlier quoted context omitted.

Or, you know, use a password manager.

Which password manager is the most secure / robust / potentially long lasting company out of: LastPass, 1Password, Dashlane, Keeper (or others?)?

I use LP, I also used 1Password professionally and I found it cumbersome but your mileage might vary. I disliked Dashlane and never used Keeper. They all do roughly the same thing, the difference is in UI mostly, just test it out and see what you like best.
Post reply on HN