Live data from Hacker News

773M Password ‘Megabreach’ Is Years Old

krebsonsecurity.com

81–90 of 177 posts

Re: 773M Password ‘Megabreach’ Is Years Old

#81
post #46
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

The best defense, just in case one of these cases turns out to be legit, is to send a video of myself watching porn to all my contacts preemptively. Take out their leverage, you know?

[deleted]

Re: 773M Password ‘Megabreach’ Is Years Old

#82
post #69
post #47

Earlier quoted context omitted.

Yea, a double video of you and what you are watching. Select the most degenerate stuff you ever watched. This would be a nightmare for basically anyone.

Personal anecdote; having your most embarrassing moments broadcast widely is good at filtering out all but your real friends. You might even find out some folks are way more understanding than you ever expected.

Those "way more understanding people" are your real friends. Congratulations for locating them!

Re: 773M Password ‘Megabreach’ Is Years Old

#83
post #34

Earlier quoted context omitted.

I received the same email to "myspace@" my domain. I wouldn't have used that email anywhere else..

Now we know where to try the associated password. Makes me think I need a better strategy on the username side to not leak that info.

I tried it on MySpace and it didn't work. Nor could I figure out what did work or what my account even is/was. I suspect MySpace has removed inactive users, though, possibly due to issues like this.

Re: 773M Password ‘Megabreach’ Is Years Old

#84
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I received 6 of these emails from October through December. They're all similar, but contain slightly different subject and body text. They refer to the same password I haven't used in a decade, although at that time I used it on a number of services, so I'm unsure of the source.

They all talk about having access to my computer, a recording of me watching porn, and threaten to send it to my contacts unless I send 700-850 USD to a Bitcoin address. The payment amounts and Bitcoin address is different in each of the emails.

Re: 773M Password ‘Megabreach’ Is Years Old

#85
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

> If he is smart he generates a different address for every single email.

1) I don't think it's one person, I've received multiple of these with different wording. At the least I think there are a bunch of copycats out there.

2) I received an initial batch of six to a few different mail addresses, and across about six different emails there was one bitcoin address used in four of them. I took a look on blockchain.info and a couple of payments of about the asked amount had gone through it in the previous few days.

What bugs me is that this is actual, criminal extortion on a large scale. Where are law enforcement?

Re: 773M Password ‘Megabreach’ Is Years Old

#86
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

Oh. Been getting these for a while. So those are actual passwords I used. I was wondering how stupid the whole thing was telling people some random string is their old password.

All the ones I've had so far have been sent to throwaway addresses with the password "monkey", so I instantly know the info comes from site I don't care about, that I probably haven't used for years.

Re: 773M Password ‘Megabreach’ Is Years Old

#87
post #4

All of the breaches are, especially these compilation ones. I switched email addresses back in 2016, and despite having accounts basically everywhere, my newer account has never showed up in a breach. Even the email address I used primarily for new accounts years before that hasn't shown up in any. Only my original created-in-2006 Gmail account ends up in breach lists.

On the topic of old email addresses, make sure your old email provider doesn't release your email address after so many years / months. This is a common way to get access to accounts by creating a new email account with the same address as an expired address and then using an email-based password reset to gain access to the account. Happened to my wife with an old email address from high school.

This is really a big problem since one is forced to keep old addresses active and around. But your email provider, even if it’s a paid service, may have stupid policies to recycle addresses very soon and may not make exceptions for you.

Posteo.de recycles deleted email addresses/aliases in three months. Fastmail is also similar and recycles them within three months or so. Same goes for Mailbox.org. All these paid services are pathetic in this regard.

Runbox.com (which I don’t use) is the only paid email service that clearly states that it never ever recycles email addresses, just like Gmail and Yahoo Mail don’t do either.

I’d like to know about privacy focused paid email services that have a clear policy of not recycling addresses.

Re: 773M Password ‘Megabreach’ Is Years Old

#89

For Troy Hunt's detailed breakdown of this particular breach: https://www.troyhunt.com/the-773-million-record-collection-1...

It just took a minute of searching to find the other collections. Does Troy wait for people to send him specific files? https://raidforums.com/Thread-Collection-1-5-Zabagur-AntiPub...

In a blog post some time back Troy mentioned that he will not pay for files on principal, because he doesn't need to financially support black hats/thieves/criminals and most of the "best" files themselves get stolen or breached (because thieves will be thieves).

I think it is a reasonable position not to pay for these files, if the money is just going to encourage the creation of more of them.

Re: 773M Password ‘Megabreach’ Is Years Old

#90
post #41
post #34

Earlier quoted context omitted.

Now we know where to try the associated password. Makes me think I need a better strategy on the username side to not leak that info.

Also it makes it easy to guess what other alias you would have used for another website. Short randomly generated hex is a much better solution.

But how will I guess my email when I do want to reconnect with my account? I see why obfuscation (well, anything to avoid predictability, up to that random hex) is advisable, but the convenience trade-off is real.
Post reply on HN