Live data from Hacker News

773M Password ‘Megabreach’ Is Years Old

krebsonsecurity.com

91–100 of 177 posts

Re: 773M Password ‘Megabreach’ Is Years Old

#91
post #88

Anyone here recommend a good security key? Is YubiKey still the best option? I noticed that they don't have any usb-c + NFC options.

I believe their upcoming HW will have support for NFC, but at this time iOS will not support NFC as MFA, though of course YK would love Apple to support them.

Correction: Looks like YK is saying iOS does support YK as MFA via NFC[1]

[1]https://www.yubico.com/2018/05/yubikey-comes-to-iphone-with-...

Re: 773M Password ‘Megabreach’ Is Years Old

#92
post #90
post #41

Earlier quoted context omitted.

Also it makes it easy to guess what other alias you would have used for another website. Short randomly generated hex is a much better solution.

But how will I guess my email when I do want to reconnect with my account? I see why obfuscation (well, anything to avoid predictability, up to that random hex) is advisable, but the convenience trade-off is real.

If you do that out of memory, you are most likely re-using passwords. Re-using passwords with an easily guessable login isn't a good combination.

Re: 773M Password ‘Megabreach’ Is Years Old

#93
post #4

Earlier quoted context omitted.

On the topic of old email addresses, make sure your old email provider doesn't release your email address after so many years / months. This is a common way to get access to accounts by creating a new email account with the same address as an expired address and then using an email-based password reset to gain access to the account. Happened to my wife with an old email address from high school.

This is really a big problem since one is forced to keep old addresses active and around. But your email provider, even if it’s a paid service, may have stupid policies to recycle addresses very soon and may not make exceptions for you. Posteo.de recycles deleted email addresses/aliases in three months. Fastmail is also similar and recycles them within three months or so. Same goes for Mailbox.org. All these paid ser…

Ideally if you're paying for email as it is, you should probably be in the custom domain space. FastMail may be able to reuse my FastMail address, but my FastMail address is tied to very little, since I use a custom domain, that they can't keep.

Of course, as a reminder: This means you have to keep your custom domain, or else someone can register it after it expires and make any emails they want on it. But if you have a domain personal to you that you've used as part of your email address, you should probably keep it forever anyways.

Re: 773M Password ‘Megabreach’ Is Years Old

#94
post #66
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I just got one with nearly the same wording. "I am aware [old password] is your passphrases. Lets get directly to point..." sent from 202.140.33.240 using the spoofed email address oo@r.com. The bitcoin address is different: 1ELzee2T9Wd5YPTYhWbWD3xK7xB5tJ94J4 Looks like the scam worked a couple times so far: https://www.blockchain.com/btc/address/1ELzee2T9Wd5YPTYhWbWD...

Yep I got a different one too, 1GjZSJnpU4AfTS8vmre6rx7eQgeMUq8VYr

Re: 773M Password ‘Megabreach’ Is Years Old

#95
post #73
post #47

Earlier quoted context omitted.

Yea, a double video of you and what you are watching. Select the most degenerate stuff you ever watched. This would be a nightmare for basically anyone.

This reminds me of the time I experimented with screen recording for self-analysis and productivity. It sometimes captured things I didn't want on video, but I forgot to turn off the recorder while I was deleting the footage. So I ended up with footage of me trying to cover up embarrassing footage.

This was probably very embarrassing and I'm sorry, but I laughed really hard at the thought of this. Thanks for making a smile this morning.

Re: 773M Password ‘Megabreach’ Is Years Old

#96
post #74

Earlier quoted context omitted.

If you're using a password manager to randomly generate long, secure passwords, the email address shouldn't matter much. The only potential issue would be social engineering to gain access to the account, but seeing how most people use the same email everywhere, I would think you'd have to a potential target for that to be of concern.

There are good reasons to provide unique aliases to companies requesting an email: - if they start sending you spam you can severe their capacity to contact you by deleting the alias - if they give your contact to a third party, you know from the alias who leaked your email address - if you see an email on a data breach like this one, you know immediately which website got hacked - it makes it really hard to correlat…

Agreed. And it's so easy to set up when you have your own domain, I'm somewhat surprised not more people are doing it. Oh well.

Re: 773M Password ‘Megabreach’ Is Years Old

#97
post #46
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

The best defense, just in case one of these cases turns out to be legit, is to send a video of myself watching porn to all my contacts preemptively. Take out their leverage, you know?

Ah, the Mark Zuckerberg model!

Re: 773M Password ‘Megabreach’ Is Years Old

#98
post #13
post #9

Earlier quoted context omitted.

I'm not aware of the specifics of the dark market, but from a marketing perspective selling something for cheap makes it easier to sell volume. Perhaps the guy who did the hack didn't want to go into the trouble of finding the one bidder who would give him top dollars, not to mention the dangers a contact like that might include. It's easier to find 1k buyers for $45 than one for $45k.

There isn't a "the guy" who did "the hack"; this is an aggregate compilation of a series of low-quality elements that have mostly lost their market value. It's the computer security equivalent of this: https://smile.amazon.com/Midnight-Movie-Madness-MegaPack-Dig... 50 low-value movies for $11.99. Note the distinction between "low value" and "no value". Yes, you might find something you like in there, as some of the r…

> It's the computer security equivalent of this: https://smile.amazon.com/Midnight-Movie-Madness-MegaPack-Dig.... 50 low-value movies for $11.99. Note the distinction between "low value" and "no value". Yes, you might find something you like in there, as some of the reviewers did, but the economic value of this stuff has passed.

They should call it "Amazon Subprime".

Re: 773M Password ‘Megabreach’ Is Years Old

#99
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

They don't reuse wallets that I've ever seen, and I've been getting spates of these off and on for a few years now, since TVTropes (what? I had some time on my hands!) got owned.

Interestingly, the dollar amount of the attempted extortion has gone up more or less monotonically throughout; the first ones I got were looking for something like $200.

Re: 773M Password ‘Megabreach’ Is Years Old

#100
post #66
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I just got one with nearly the same wording. "I am aware [old password] is your passphrases. Lets get directly to point..." sent from 202.140.33.240 using the spoofed email address oo@r.com. The bitcoin address is different: 1ELzee2T9Wd5YPTYhWbWD3xK7xB5tJ94J4 Looks like the scam worked a couple times so far: https://www.blockchain.com/btc/address/1ELzee2T9Wd5YPTYhWbWD...

Oh, interesting! I've never seen anyone running this scam reuse a wallet before.
Post reply on HN