Live data from Hacker News

773M Password ‘Megabreach’ Is Years Old

krebsonsecurity.com

71–80 of 177 posts

Re: 773M Password ‘Megabreach’ Is Years Old

#71
post #66
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I just got one with nearly the same wording. "I am aware [old password] is your passphrases. Lets get directly to point..." sent from 202.140.33.240 using the spoofed email address oo@r.com. The bitcoin address is different: 1ELzee2T9Wd5YPTYhWbWD3xK7xB5tJ94J4 Looks like the scam worked a couple times so far: https://www.blockchain.com/btc/address/1ELzee2T9Wd5YPTYhWbWD...

[deleted]

Re: 773M Password ‘Megabreach’ Is Years Old

#72

Earlier quoted context omitted.

> recorded watching porn What a damning position to be in, in 2019.

Unless it's a black mirror twist. Next thing you're following some trolls orders to kill people to conceal your dark secret

yea, umm.... that wasn't regular porn he was watching

Re: 773M Password ‘Megabreach’ Is Years Old

#73
post #47
post #46

Earlier quoted context omitted.

The best defense, just in case one of these cases turns out to be legit, is to send a video of myself watching porn to all my contacts preemptively. Take out their leverage, you know?

Yea, a double video of you and what you are watching. Select the most degenerate stuff you ever watched. This would be a nightmare for basically anyone.

This reminds me of the time I experimented with screen recording for self-analysis and productivity. It sometimes captured things I didn't want on video, but I forgot to turn off the recorder while I was deleting the footage. So I ended up with footage of me trying to cover up embarrassing footage.

Re: 773M Password ‘Megabreach’ Is Years Old

#74
post #41

Earlier quoted context omitted.

Also it makes it easy to guess what other alias you would have used for another website. Short randomly generated hex is a much better solution.

If you're using a password manager to randomly generate long, secure passwords, the email address shouldn't matter much. The only potential issue would be social engineering to gain access to the account, but seeing how most people use the same email everywhere, I would think you'd have to a potential target for that to be of concern.

There are good reasons to provide unique aliases to companies requesting an email:

- if they start sending you spam you can severe their capacity to contact you by deleting the alias

- if they give your contact to a third party, you know from the alias who leaked your email address

- if you see an email on a data breach like this one, you know immediately which website got hacked

- it makes it really hard to correlate your identity across two websites

Re: 773M Password ‘Megabreach’ Is Years Old

#76

Earlier quoted context omitted.

> recorded watching porn What a damning position to be in, in 2019.

Email a million addresses and you'll wind up hitting a few who've been browsing child porn, or something they'd find highly embarrassing if their parents/spouse/SO found out. As with other scams that can be initiated at scale, you don't need a 50% conversion rate. 0.01% probably suits just fine.

A conversion rate of 0.01% on 700 million addresses and a ~$1000 demand makes you 70million dollar. That's a lot of money for just sending 700 million emails.

Re: 773M Password ‘Megabreach’ Is Years Old

#77
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

How can the authorities blacklist a Bitcoin wallet address? Couldn't he just tumble the coins and spread them far and wide?

Re: 773M Password ‘Megabreach’ Is Years Old

#78
post #51

I think they are also trying to use the same credentials to log in to accounts. I got an email from Epic Game saying there are too many failed login attempts, so it was suspended. Ironically, I don't even remember having one. So I logged into the account and made sure there none of the information on there were personal.

Did you click on the link in the email to log in? That's another one to be aware of, fake clone websites linked to fake emails purporting to be from the company.

Always go directly to the site using your bookmarks or typing it in, or at least remember to check the url before you click it.

Re: 773M Password ‘Megabreach’ Is Years Old

#79

Earlier quoted context omitted.

The screenshot has a tab open on this article: https://www.troyhunt.com/the-773-million-record-collection-1... I don't think it's from the seller - looks like it was taken by the author of this article.

It addresses that in the article: "...notice the open Web browser tab behind his purloined password trove (which is apparently stored at Mega.nz): Troy Hunt’s published research on this 773 million Collection #1"

Sooo this is either a screenshot of Sanixer's machine or of someone who has access to his entire trove. Clearly not the author's.

I see the mega.nz handle "Louren KINGUR" with avatar, and the same person's Google account avatar with no username. I did an image search on this latter one and came up empty handed, but maybe someone with more finesse could find him this way.

Re: 773M Password ‘Megabreach’ Is Years Old

#80
post #38

I was terrified of my old email being compromised because somebody tried logging into it from Windows (I don't use Windows) and because I had an identity theft scare a month back. What I'm doing going forward is having a personal email acct I don't give out (with 2FA thru U2F), and creating burner GMail accounts that forward emails to that email using POP3. I'm already pwned because I use my personal email for a lot…

Adding a bit of security on the identification side (usernames/emails) isn't completely useless, but the focus should be on securing authentication. I.e. never use a password twice and add 2FA to everything even vaguely important to you. With password managers that's also way easier than managing a lot of email accounts.

I use Bitwarden, password autogen, and 2FA to manage those too, though I'm not fully migrated over yet (still have a lot of weak duplicate passwords). My problem is the older services I have to use that don't support 2FA.
Post reply on HN