So the seller shows a screenshot with browser tabs, a date and a time. One of the tabs is really very specific, looking at a particular disqus profile. I'm not familiar with Windows; is there anything in the screenshot to suggest its torbrowser or anything like that? Presumably the miscreant's ISP and e.g. the Russian government can guess real easy whom generated that screenshot...? Of course what they'd do with that…
773M Password ‘Megabreach’ Is Years Old
11–20 of 177 posts
Re: 773M Password ‘Megabreach’ Is Years Old
#12So the seller shows a screenshot with browser tabs, a date and a time. One of the tabs is really very specific, looking at a particular disqus profile. I'm not familiar with Windows; is there anything in the screenshot to suggest its torbrowser or anything like that? Presumably the miscreant's ISP and e.g. the Russian government can guess real easy whom generated that screenshot...? Of course what they'd do with that…
I don't think it's from the seller - looks like it was taken by the author of this article.
Re: 773M Password ‘Megabreach’ Is Years Old
#13Earlier quoted context omitted.
In all seriousness, the reason why this and several collections roughly as large as it went for $45 on the market is precisely that it must not be that useful anymore. If it truly were a skeleton key to the world it would not be going for $45. I'm abundantly positive there's still a lot of perfectly valid login credentials in there, but the trick is finding them without also triggering rate limiting detection now.
I'm not aware of the specifics of the dark market, but from a marketing perspective selling something for cheap makes it easier to sell volume. Perhaps the guy who did the hack didn't want to go into the trouble of finding the one bidder who would give him top dollars, not to mention the dangers a contact like that might include. It's easier to find 1k buyers for $45 than one for $45k.
My point is that the market value has been lost because there actually is some churn in passwords and accounts. If 99% of the credentials in this hack still worked, it would not be getting sold at this price at all; it would be selling something worth tens or hundreds of thousands, if not millions to the right buyer, for You Pay Only $44.99. Not gonna happen. It can't be worth all that much to most buyers if that's all they're selling it for.
Or it's just so widespread that it's worthless, although I'd suggest in that case that we'd have heard about it earlier. Have I Been Pwned actually has some hookups in that world.
Re: 773M Password ‘Megabreach’ Is Years Old
#14Re: 773M Password ‘Megabreach’ Is Years Old
#15Re: 773M Password ‘Megabreach’ Is Years Old
#16Re: 773M Password ‘Megabreach’ Is Years Old
#17Earlier quoted context omitted.
I'm not aware of the specifics of the dark market, but from a marketing perspective selling something for cheap makes it easier to sell volume. Perhaps the guy who did the hack didn't want to go into the trouble of finding the one bidder who would give him top dollars, not to mention the dangers a contact like that might include. It's easier to find 1k buyers for $45 than one for $45k.
There isn't a "the guy" who did "the hack"; this is an aggregate compilation of a series of low-quality elements that have mostly lost their market value. It's the computer security equivalent of this: https://smile.amazon.com/Midnight-Movie-Madness-MegaPack-Dig... 50 low-value movies for $11.99. Note the distinction between "low value" and "no value". Yes, you might find something you like in there, as some of the r…
Re: 773M Password ‘Megabreach’ Is Years Old
#18> I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You don't know me and you're most likely wondering why you are getting this e-mail?
He continues to tell me my computer was hacked using that password, he downloaded my contacts, recorded me watching porn and now threatens me to send that video to all my contacts. Of course unless I send him bitcoins for about $1000 to 1EiJMyvw2NP6T6vyWQ81HgUfBUVT1mqZkM
I got multiple of these emails in my spam folder since December. The password comes most likely from the Heroes of Newerth leak back in 2014!
It's obviously a scam no one should respond to, but I'm sure there is a large enough number of people that get intimidated enough and are actually buying and sending bitcoins. This is a real threat these collections create. To be honest I feel uneasy about this email though I'm 100% sure this password is not used for anything important since about two years ago. I can't imagine how someone with a current password and no security/compsci knowledge at all would feel.
I unfortunately deleted all but the last of this emails, so I wonder if he reuses the same bitcoin address and it can be easily blacklisted by authorities. If he is smart he generates a different address for every single email.
Re: 773M Password ‘Megabreach’ Is Years Old
#19I know best practice is to immediately change your password regardless, but with the increasing frequency of these kinds of breaches and the reuse and recombination of old lists, how long will it be before emails from leak notification sites like haveibeenpwned start becoming so frequent that people start ignoring them? I am already more guilty of that than I'd like to admit, even though I should know better.
I know there are various places you can check a given password against known leak lists, but it makes me really uncomfortable typing my password into anyplace which is not a password manager or the site it's used for - enough that I want to change it afterwards anyway.
I already hear the arguments that none of this matters if you follow best practices, which are not wrong, but I've always gone with the option which is as secure as possible without being overly burdensome, and I'm sure I'm not the only one.
Re: 773M Password ‘Megabreach’ Is Years Old
#20Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…