Live data from Hacker News

Data Leak Exposes 149M Logins, Including Gmail, Facebook

techrepublic.com

21–29 of 29 posts

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#21
post #14
post #12

It should be a standard practice to have a unique email and password for every service you use out there, plus the usual like 2FA. I have been doing this for years and never had any issue, but also you can tell if the service got compromised even if they never announced it. For example, I have an account on a service called Shakepay, and recently I have been getting a lot of phishing attempts on that specific unique…

How do you manage having potentially many different email accounts?

Outlook supports having multiple arbitrary email addresses as well as allowing login from only one of them.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#22

So I just searched my email on HIBP again. Most of the leaks I see there were from old websites I hardly cared about securing from many years ago. But, in general, how do I find out what has actually been leaked (if it's not website specific)? I'm not going to change all of my passwords every time a random website that I used briefly ten years ago leaks my low effort password.

Each site should ideally have a unique password so you only need to change that one.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#23
post #14
post #12

It should be a standard practice to have a unique email and password for every service you use out there, plus the usual like 2FA. I have been doing this for years and never had any issue, but also you can tell if the service got compromised even if they never announced it. For example, I have an account on a service called Shakepay, and recently I have been getting a lot of phishing attempts on that specific unique…

How do you manage having potentially many different email accounts?

It's only 1 email account but with either catch-all or aliases configured.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#24
post #20

Earlier quoted context omitted.

You shouldn't have to change any passwords on other sites because you shouldn't be reusing passwords.

I use separate emails for all accounts and that get's me in trouble when companies "consolidate" accounts because "everyone uses the same email for all accounts". Your good idea might be true, practice is not. I've had this twice now in one year ...

The parent was talking about different passwords, not different emails. But I'm curious, what does it mean for a company to consolidate accounts? How would that be done to your separate accounts automatically, and what trouble does it cause? And what is the normal case where people have multiple accounts all with the same email?

I just don't understand the circumstance you're describing.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#25

IMHO, any password shared with google and/or Facebook is instantly "leaked". I trust them less with my passwords than I do randos.

I don't understand, why do you say this? I would think that google's security is very solid, and am not aware of them ever being hacked to gain access to user accounts/passwords. Are you saying they're deliberately leaking user passwords to 3rd parties?

It isn't that they leak to others. I DWAN not like them knowing my passwords, even if they are necessary. I'd rather not have to deal with them.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#26
post #22

So I just searched my email on HIBP again. Most of the leaks I see there were from old websites I hardly cared about securing from many years ago. But, in general, how do I find out what has actually been leaked (if it's not website specific)? I'm not going to change all of my passwords every time a random website that I used briefly ten years ago leaks my low effort password.

Each site should ideally have a unique password so you only need to change that one.

Exactly! Then you write each password down in your notebook of passwords and pat yourself on the back for how hard it would be to compromise all your accounts in one go ;)

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#27

So I just searched my email on HIBP again. Most of the leaks I see there were from old websites I hardly cared about securing from many years ago. But, in general, how do I find out what has actually been leaked (if it's not website specific)? I'm not going to change all of my passwords every time a random website that I used briefly ten years ago leaks my low effort password.

There are sites for searching for your (or anyone else's) publicly revealed information, but the one free one I knew of was forced offline.

Downloading the datasets--there are so many with so few options to obtain them. The mega-compilations likely won't include everything, either, like your license plate numbers or all your compromised addresses, nor the site from which hackers stole it.

So basically don't bother. If you want the same experience, open up notepad, HIBP, and your password manager, and make a little doxx file on yourself, in CSV or JSON.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#28
post #19
post #15

Earlier quoted context omitted.

Just adding plus signs and the vendor name in the address would do it.

isn’t this easy for a potential attacker to mitigate, i.e. dropping from the address everything after the plus? it’s a known trick for gmail so i would not be surprised if an attacker knew how to get to the “real” address by cleaning it up.

Yes, even some attackers I noticed they excluded all custom domains from their dumps to avoid alerting individuals before they sell it. It’s why it’s better to have a fully unique email, preferably masked one (not custom domains) as some email services provider do, so you get the isolation feature but also blending in without going noticed by attackers.

Re: Data Leak Exposes 149M Logins, Including Gmail, Facebook

#29
post #22

Earlier quoted context omitted.

Each site should ideally have a unique password so you only need to change that one.

Exactly! Then you write each password down in your notebook of passwords and pat yourself on the back for how hard it would be to compromise all your accounts in one go ;)

Well hopefully you're using something with client side encryption and not a plain text notebook!
Post reply on HN