Live data from Hacker News

773M Password ‘Megabreach’ Is Years Old

krebsonsecurity.com

151–160 of 177 posts

Re: 773M Password ‘Megabreach’ Is Years Old

#151
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I have received a few of these as well (all displaying the same password). Because I use a unique, random password for every site, it was just a matter of finding it my password manager. In my case, it was an old one from a forum breech several years ago (not in any way related to porn).

It's clear that someone has made a business model out of this, and it doesn't matter what the password is actually from. For people that don't use unique passwords, they can't say if there is anything behind the threat.

Remember to always use unique passwords for every site!

Re: 773M Password ‘Megabreach’ Is Years Old

#152
post #131
post #105

Earlier quoted context omitted.

They do have NFC and usb-c options (separately, though), and are planning to launch lightning as well https://www.yubico.com/2019/01/yubico-launches-the-security-...

Yes, I was looking for USB+C + NFC, so I can use it with my Macbook + iPhone... having to buy two seems inconvenient.

Note that you will want to own at least two and enroll both of them to properly lock down a service so that it doesn't need some plan B. The reason is that obviously if it's locked down to a single U2F Security Key and that key breaks or is lost you're screwed.

Google's programme aimed at high risk people (e.g. journalists covering government corruption) specifically aims to leave you in a position where so long as you have control over the physical devices your secrets are safe, and if the devices are destroyed then your account is irrevocably lost and too bad. Doing that with just one key is asking for trouble.

If you're just dipping your toe in the water, buying one key and having your plan B be a bunch of one time codes written in the back of a diary in your locked desk drawer makes sense, and if you're mostly just interested in the cool technology and not worried about security then going to a Key with Google Authenticator as plan B is fine too.

But if you want this to solve all your problems as advertised, buy two keys.

Re: 773M Password ‘Megabreach’ Is Years Old

#153
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

This is a new variant of the porn-blackmail scam, I've been receiving similar E-mails since 2017 after the Bitcoin fever. I guess the scammers have gotten their inspiration from watching Black Mirror since then.

Re: 773M Password ‘Megabreach’ Is Years Old

#154

Earlier quoted context omitted.

I use Bitwarden, password autogen, and 2FA to manage those too, though I'm not fully migrated over yet (still have a lot of weak duplicate passwords). My problem is the older services I have to use that don't support 2FA.

In all honesty, it's probably not worth worrying about. The implementation of 2FA you're referring to here is just adding a 2nd secret, with a small twist of having time component. There are very few scenarios where your (high entropy) password would be compromised in a way that wouldn't also lead to the discovery of at least 1 functional 2FA code. 1) Website is breached. If they can get the account password hashes,…

I’ve been robbed six times, including once where one third of my money disappeared. I agree with you that security is only as strong as its weakest link. I just take emotional comfort in doing everything I can to make myself more prickly and less vulnerable.

Re: 773M Password ‘Megabreach’ Is Years Old

#155
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

Yeah, I started getting those a few weeks back as well. The password is my old intranet password from my elementary school, funnily enough. I sent their admin an email about it, but I've heard nothing back so w/ev.

Re: 773M Password ‘Megabreach’ Is Years Old

#156
post #44
post #41

Earlier quoted context omitted.

Also it makes it easy to guess what other alias you would have used for another website. Short randomly generated hex is a much better solution.

There is a pretty cool keepass plugin [1] that generates randomly generated readable passwords based on a dictionary with definitions of nouns, verbs and adjectives and multiple patterns to create short sentences. Even if the dictionary and patterns are known by an attacker, this still has very good entropy on ~16 characters long sentences. For usernames you can easily just go down to the minimum (around 6-10). I fin…

Also available as a 1Password feature. It's inspired by the XKCD "correct horse battery staple" comic.

Re: 773M Password ‘Megabreach’ Is Years Old

#157
post #125
post #94

Earlier quoted context omitted.

Yep I got a different one too, 1GjZSJnpU4AfTS8vmre6rx7eQgeMUq8VYr

Different too for me 1KeCBKUgQDyyMpaXhfpRi2qUvyrjcsT44o

Quick search turned up 5 unique wallets for me :\

    1EaqpQL5AoCb6iuPhiRx1urzDV1MUo9AWd
    1PTGiBdKsZdHxBm4961tTToqiA7B8fy3ZN
    15ZHnf1MPn6ybb8yUeAoCQ1AJtiKhg3NrP
    1DtNv1T1RUwjTCdSjNmmosbpCvBQ4shgVz
    1MAM6oPcycTrfiLPS9tjtAR8t6KDmL91fr

Re: 773M Password ‘Megabreach’ Is Years Old

#158

Earlier quoted context omitted.

In all honesty, it's probably not worth worrying about. The implementation of 2FA you're referring to here is just adding a 2nd secret, with a small twist of having time component. There are very few scenarios where your (high entropy) password would be compromised in a way that wouldn't also lead to the discovery of at least 1 functional 2FA code. 1) Website is breached. If they can get the account password hashes,…

I’ve been robbed six times, including once where one third of my money disappeared. I agree with you that security is only as strong as its weakest link. I just take emotional comfort in doing everything I can to make myself more prickly and less vulnerable.

Thats scary. If you have been robbed six times, your operational security is probably pretty weak. Unless you are some kind of high value asset.

Would be curious to learn more about how it happened, to see if there are any learnings for myself to improve operational security.

Re: 773M Password ‘Megabreach’ Is Years Old

#160
post #57
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I think it's interesting that they're trying to get non-technical people who would fall for this kind of thing to buy bitcoins and then send them. Like the number of people who would believe this, have a thousand dollars on hand, and be able to buy and send bitcoins is probably tiny.

Market making at its finest! /s
Post reply on HN