Earlier quoted context omitted.
I received the same email to "myspace@" my domain. I wouldn't have used that email anywhere else..
Now we know where to try the associated password. Makes me think I need a better strategy on the username side to not leak that info.
773M Password ‘Megabreach’ Is Years Old
41–50 of 177 posts
Re: 773M Password ‘Megabreach’ Is Years Old
#42Earlier quoted context omitted.
I received the same email to "myspace@" my domain. I wouldn't have used that email anywhere else..
Now we know where to try the associated password. Makes me think I need a better strategy on the username side to not leak that info.
Re: 773M Password ‘Megabreach’ Is Years Old
#43Re: 773M Password ‘Megabreach’ Is Years Old
#44Earlier quoted context omitted.
Now we know where to try the associated password. Makes me think I need a better strategy on the username side to not leak that info.
Also it makes it easy to guess what other alias you would have used for another website. Short randomly generated hex is a much better solution.
Even if the dictionary and patterns are known by an attacker, this still has very good entropy on ~16 characters long sentences. For usernames you can easily just go down to the minimum (around 6-10).
I find this superior to random values in a lot of places as it's easily readable and it's also easily typeable, when copy-paste doesn't work.
[1] https://bitbucket.org/ligos/readablepassphrasegenerator/wiki...
Re: 773M Password ‘Megabreach’ Is Years Old
#45Earlier quoted context omitted.
Now we know where to try the associated password. Makes me think I need a better strategy on the username side to not leak that info.
Also it makes it easy to guess what other alias you would have used for another website. Short randomly generated hex is a much better solution.
Re: 773M Password ‘Megabreach’ Is Years Old
#46Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…
Re: 773M Password ‘Megabreach’ Is Years Old
#47Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…
The best defense, just in case one of these cases turns out to be legit, is to send a video of myself watching porn to all my contacts preemptively. Take out their leverage, you know?
This would be a nightmare for basically anyone.
Re: 773M Password ‘Megabreach’ Is Years Old
#48Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…
I've had 3 web clients contact me that received these. One called the local police, and an IT guy, two bought new computers, and one I never hard back from.
Re: 773M Password ‘Megabreach’ Is Years Old
#49Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…
Re: 773M Password ‘Megabreach’ Is Years Old
#50Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…
So I can confirm that scammers seem to leverage password dumps that way. It's quite clever I suppose, if I used the same password everywhere (as many people seem to do) I'd definitely be worried.