Live data from Hacker News

773M Password ‘Megabreach’ Is Years Old

krebsonsecurity.com

41–50 of 177 posts

Re: 773M Password ‘Megabreach’ Is Years Old

#41
post #34

Earlier quoted context omitted.

I received the same email to "myspace@" my domain. I wouldn't have used that email anywhere else..

Now we know where to try the associated password. Makes me think I need a better strategy on the username side to not leak that info.

Also it makes it easy to guess what other alias you would have used for another website. Short randomly generated hex is a much better solution.

Re: 773M Password ‘Megabreach’ Is Years Old

#42
post #34

Earlier quoted context omitted.

I received the same email to "myspace@" my domain. I wouldn't have used that email anywhere else..

Now we know where to try the associated password. Makes me think I need a better strategy on the username side to not leak that info.

If you're using a password manager you could generate a random local-part and store that too.

Re: 773M Password ‘Megabreach’ Is Years Old

#44
post #41
post #34

Earlier quoted context omitted.

Now we know where to try the associated password. Makes me think I need a better strategy on the username side to not leak that info.

Also it makes it easy to guess what other alias you would have used for another website. Short randomly generated hex is a much better solution.

There is a pretty cool keepass plugin [1] that generates randomly generated readable passwords based on a dictionary with definitions of nouns, verbs and adjectives and multiple patterns to create short sentences.

Even if the dictionary and patterns are known by an attacker, this still has very good entropy on ~16 characters long sentences. For usernames you can easily just go down to the minimum (around 6-10).

I find this superior to random values in a lot of places as it's easily readable and it's also easily typeable, when copy-paste doesn't work.

[1] https://bitbucket.org/ligos/readablepassphrasegenerator/wiki...

Re: 773M Password ‘Megabreach’ Is Years Old

#45
post #41
post #34

Earlier quoted context omitted.

Now we know where to try the associated password. Makes me think I need a better strategy on the username side to not leak that info.

Also it makes it easy to guess what other alias you would have used for another website. Short randomly generated hex is a much better solution.

If you're using a password manager to randomly generate long, secure passwords, the email address shouldn't matter much. The only potential issue would be social engineering to gain access to the account, but seeing how most people use the same email everywhere, I would think you'd have to a potential target for that to be of concern.

Re: 773M Password ‘Megabreach’ Is Years Old

#46
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

The best defense, just in case one of these cases turns out to be legit, is to send a video of myself watching porn to all my contacts preemptively. Take out their leverage, you know?

Re: 773M Password ‘Megabreach’ Is Years Old

#47
post #46
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

The best defense, just in case one of these cases turns out to be legit, is to send a video of myself watching porn to all my contacts preemptively. Take out their leverage, you know?

Yea, a double video of you and what you are watching. Select the most degenerate stuff you ever watched.

This would be a nightmare for basically anyone.

Re: 773M Password ‘Megabreach’ Is Years Old

#48
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

> It's obviously a scam no one should respond to, but I'm sure there is a large enough number of people that get intimidated enough and are actually buying and sending bitcoins

I've had 3 web clients contact me that received these. One called the local police, and an IT guy, two bought new computers, and one I never hard back from.

Re: 773M Password ‘Megabreach’ Is Years Old

#49
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

Oh. Been getting these for a while. So those are actual passwords I used. I was wondering how stupid the whole thing was telling people some random string is their old password.

Re: 773M Password ‘Megabreach’ Is Years Old

#50
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I've been receiving similar emails for a long time (probably more than a year) with my old Linkedin account password that was part of the 2012 breach. I don't even have a LinkedIn account anymore and I know that I haven't used the password anywhere else since it was randomly generated for that website by my password manager.

So I can confirm that scammers seem to leverage password dumps that way. It's quite clever I suppose, if I used the same password everywhere (as many people seem to do) I'd definitely be worried.

Post reply on HN