Live data from Hacker News

773M Password ‘Megabreach’ Is Years Old

krebsonsecurity.com

131–140 of 177 posts

Re: 773M Password ‘Megabreach’ Is Years Old

#131
post #105
post #88

Anyone here recommend a good security key? Is YubiKey still the best option? I noticed that they don't have any usb-c + NFC options.

They do have NFC and usb-c options (separately, though), and are planning to launch lightning as well https://www.yubico.com/2019/01/yubico-launches-the-security-...

Yes, I was looking for USB+C + NFC, so I can use it with my Macbook + iPhone... having to buy two seems inconvenient.

Re: 773M Password ‘Megabreach’ Is Years Old

#132
post #91
post #88

Anyone here recommend a good security key? Is YubiKey still the best option? I noticed that they don't have any usb-c + NFC options.

I believe their upcoming HW will have support for NFC, but at this time iOS will not support NFC as MFA, though of course YK would love Apple to support them. Correction: Looks like YK is saying iOS does support YK as MFA via NFC[1] [1] https://www.yubico.com/2018/05/yubikey-comes-to-iphone-with-...

If anyone had a chance of getting Apple to approve NFC for MFA, it’s Yunikey. But I wouldn’t hold my breathe just yet and would plan on the lightening one.

Re: 773M Password ‘Megabreach’ Is Years Old

#133
post #123

Earlier quoted context omitted.

I've used KeePass and one issue I do take with it is the UX. Bitwarden and 1password feel like cohesive apps and have good integration with many platforms. For KeePass I felt uneasy about some of the ports of it. There's a lot of good ones on desktop, less so on mobile. Syncing is also a thing I prefer 1password and Bitwarden for. They both have cloud syncing by default. Some won't want that but I definitely do.

The problem I personally have with KeePass is sharing and that you are on your own for many things. You CAN make mistakes with KeePass. You pretty much can’t make mistakes with a service. I’ve set about 100 people up on LastPass including my mom. I recommend it as a very good thing normal people will actually use.

I used to recommend LastPass but I had to stop recommending it based on their responses to issues including security issues. You can see some instances on the Mozilla bug tracker. It also has had a bad track record with security issues. There was an RCE on the browser extensions in 2017.

Re: 773M Password ‘Megabreach’ Is Years Old

#134
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I received the same email to "myspace@" my domain. I wouldn't have used that email anywhere else..

I've had the same one to nexus@ mydomain which I suspect I used when I was doing phone dev on a forum or manufacturers website. I'd love to know which site it was that leaked.

Re: 773M Password ‘Megabreach’ Is Years Old

#135
post #129

Naive soul here, but is it really wise to type live passwords into someone's site that ostensibly is looking for matches with its existing database? That seems awfully trusting.

The reasoning given is: if you're aware it's a bad idea, great! Don't do it. If you don't yet know it's a bad idea, and do it, you'll see how many places it has already been leaked, and hopefully start using different passwords, and a password manager ...

Re: 773M Password ‘Megabreach’ Is Years Old

#136
post #129

Naive soul here, but is it really wise to type live passwords into someone's site that ostensibly is looking for matches with its existing database? That seems awfully trusting.

Troy Hunt's haveibeenpwned has a password checking facility at https://haveibeenpwned.com/Passwords

He describes the security measures behind the process here:

https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...

Of course, it all still boils down to how much you trust the guy, the approach, etc etc.

Re: 773M Password ‘Megabreach’ Is Years Old

#137
post #96
post #74

Earlier quoted context omitted.

There are good reasons to provide unique aliases to companies requesting an email: - if they start sending you spam you can severe their capacity to contact you by deleting the alias - if they give your contact to a third party, you know from the alias who leaked your email address - if you see an email on a data breach like this one, you know immediately which website got hacked - it makes it really hard to correlat…

Agreed. And it's so easy to set up when you have your own domain, I'm somewhat surprised not more people are doing it. Oh well.

It would be cool if there was something like this built into a password manager

Re: 773M Password ‘Megabreach’ Is Years Old

#138
post #129

Naive soul here, but is it really wise to type live passwords into someone's site that ostensibly is looking for matches with its existing database? That seems awfully trusting.

The reasoning given is: if you're aware it's a bad idea, great! Don't do it. If you don't yet know it's a bad idea, and do it, you'll see how many places it has already been leaked, and hopefully start using different passwords, and a password manager ...

It trains average/non-IT people to enter their password on websites to “check”. If scammers start setting up mock websites that ask you to enter your password to see if your account was hacked, people will fall for it because they have been trained by white-hats that this is an acceptable practice.

Re: 773M Password ‘Megabreach’ Is Years Old

#139
post #46
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

The best defense, just in case one of these cases turns out to be legit, is to send a video of myself watching porn to all my contacts preemptively. Take out their leverage, you know?

The most revealing thing in that video would be how bored I get from porn these days.

Re: 773M Password ‘Megabreach’ Is Years Old

#140
post #92
post #90

Earlier quoted context omitted.

But how will I guess my email when I do want to reconnect with my account? I see why obfuscation (well, anything to avoid predictability, up to that random hex) is advisable, but the convenience trade-off is real.

If you do that out of memory, you are most likely re-using passwords. Re-using passwords with an easily guessable login isn't a good combination.

Re-using passwords with a unique login would indeed be stupid because it would not only be weak against attackers but also have terrible ergonomics: it's usually much easier to regain access after forgetting the password than to regain access after forgetting the login. Source: I often forget both of them.

What I and many others do is reuse not a password, but reuse a password formula (in my case with slight but easily memorable variations depending on importance, or if forced by stupid password rules). If you saw a dozen of my email/password combinations in the clear you would be able to reverse engineer the rules and then guess combinations for arbitrary sites almost as good as me. It's a calculated risk, just like trusting a password manager is a calculated risk. Right now I consider password managers the better trade-off, but still only slightly better, by a margin small enough to make it not worthwhile to invest in a habit change. If the "formula" I happen to use was just a little harder to reverse engineer than it sadly is I would consider it strictly safer than password managers.

Post reply on HN