Live data from Hacker News

Data Leak Exposes 149M Logins, Including Gmail, Facebook

techrepublic.com

11–20 of 29 posts

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#12
It should be a standard practice to have a unique email and password for every service you use out there, plus the usual like 2FA. I have been doing this for years and never had any issue, but also you can tell if the service got compromised even if they never announced it. For example, I have an account on a service called Shakepay, and recently I have been getting a lot of phishing attempts on that specific unique email that's never been used anywhere else. I can tell for certain that their email database got leaked/they sold it.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#13

IMHO, any password shared with google and/or Facebook is instantly "leaked". I trust them less with my passwords than I do randos.

Companies trust them with their passwords and intellectual property and remain in business. It's insane to me too, but that's the world we actually live in

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#14
post #12

It should be a standard practice to have a unique email and password for every service you use out there, plus the usual like 2FA. I have been doing this for years and never had any issue, but also you can tell if the service got compromised even if they never announced it. For example, I have an account on a service called Shakepay, and recently I have been getting a lot of phishing attempts on that specific unique…

How do you manage having potentially many different email accounts?

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#15
post #14
post #12

It should be a standard practice to have a unique email and password for every service you use out there, plus the usual like 2FA. I have been doing this for years and never had any issue, but also you can tell if the service got compromised even if they never announced it. For example, I have an account on a service called Shakepay, and recently I have been getting a lot of phishing attempts on that specific unique…

How do you manage having potentially many different email accounts?

Just adding plus signs and the vendor name in the address would do it.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#16
So I just searched my email on HIBP again. Most of the leaks I see there were from old websites I hardly cared about securing from many years ago. But, in general, how do I find out what has actually been leaked (if it's not website specific)?

I'm not going to change all of my passwords every time a random website that I used briefly ten years ago leaks my low effort password.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#17
post #14
post #12

It should be a standard practice to have a unique email and password for every service you use out there, plus the usual like 2FA. I have been doing this for years and never had any issue, but also you can tell if the service got compromised even if they never announced it. For example, I have an account on a service called Shakepay, and recently I have been getting a lot of phishing attempts on that specific unique…

How do you manage having potentially many different email accounts?

A lot of email services that provide the aliasing feature have seamless integration with password managers, so when you sign up you generate a unique email and password on the fly, and it get saved in the manager.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#18

So I just searched my email on HIBP again. Most of the leaks I see there were from old websites I hardly cared about securing from many years ago. But, in general, how do I find out what has actually been leaked (if it's not website specific)? I'm not going to change all of my passwords every time a random website that I used briefly ten years ago leaks my low effort password.

You shouldn't have to change any passwords on other sites because you shouldn't be reusing passwords.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#19
post #15
post #14

Earlier quoted context omitted.

How do you manage having potentially many different email accounts?

Just adding plus signs and the vendor name in the address would do it.

isn’t this easy for a potential attacker to mitigate, i.e. dropping from the address everything after the plus? it’s a known trick for gmail so i would not be surprised if an attacker knew how to get to the “real” address by cleaning it up.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#20

So I just searched my email on HIBP again. Most of the leaks I see there were from old websites I hardly cared about securing from many years ago. But, in general, how do I find out what has actually been leaked (if it's not website specific)? I'm not going to change all of my passwords every time a random website that I used briefly ten years ago leaks my low effort password.

You shouldn't have to change any passwords on other sites because you shouldn't be reusing passwords.

I use separate emails for all accounts and that get's me in trouble when companies "consolidate" accounts because "everyone uses the same email for all accounts". Your good idea might be true, practice is not.

I've had this twice now in one year ...

Post reply on HN