Live data from Hacker News

Two million Facebook, Gmail and Twitter passwords stolen

money.cnn.com

31–40 of 107 posts

Re: Two million Facebook, Gmail and Twitter passwords stolen

#32

What platform(s) was the keylogger written for and how was it spread?

Given the vast amount of passwords farmed, I would say it was targetted for the Windows platform.

Is this really a valid point still? Surely two million is a drop in the bucket in the group of Facebook users accessing via OS X or Windows.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#33
post #22

57.06% of the passwords stolen were for the Facebook domain. Sigh!

At least nothing of value was lost?

The ADP -- a payroll service -- passwords (which, interestingly, aren't in the headline), are probably the ones that, despite being smallest in number, offer the most opportunity for direct financial disruption.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#35
post #22

Earlier quoted context omitted.

At least nothing of value was lost?

The ADP -- a payroll service -- passwords (which, interestingly, aren't in the headline), are probably the ones that, despite being smallest in number, offer the most opportunity for direct financial disruption.

ADP is horrible, but their website can't change financial details (it only shows paystubs and tax forms). You can kinda change things through ADP FlexDirect, but all direct deposit enrollment is done elsewhere.

The ADP employee site hasn't changed in the past ten years and still uses basic auth. It's horrible. And freaky. When you login to your new company account, it shows all paystubs from your past employers too. [With the implication of your current payroll department being able to see how much you were getting paid at all your previous jobs since it's the same account?]

Re: Two million Facebook, Gmail and Twitter passwords stolen

#36
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

Yup, exactly why I made https://GAuthify.com , keep it standard via Google Authenticator and allow other options like SMS, Voice and Email. If you want to add it to your app and can't afford it, shoot support and email and I'll try to set you up with a discount/free-er account.

GAuthify is great. Super easy to implement (libraries in almost all major languages), and supports auth mechanisms via (GA, SMS, Voice, and E-Mail).

Re: Two million Facebook, Gmail and Twitter passwords stolen

#38

Earlier quoted context omitted.

What happens if I'm i) outside the country, so no SMS for me, ii) outside cell tower coverage but with wifi (happens every day for me inside buildings), or I got my cellphone stolen for instance. How does 2fauth works in that case? (Just wondering, as the above are the reasons I decided not to use it)

2-factor authentication does not require the second factor every time. It typically only asks for the second factor if the device is unrecognized, or the usage pattern is unfamiliar. So, your laptop that's logged into GMail will stay logged in when you're out of the country. Unless you explicitly log out, it will stay this way. I enter maybe one two-factor auth code a week, if that. So: i) Prepare ahead and log into…

All the 2-factor entry boxes I've seen make the "trust" optional. If you want to be asked every time, just uncheck the box.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#39
post #31

Ugh. Actually, 410k Facebook, Gmail, and Twitter passwords stolen: 318,000 Facebook accounts 70,000 Gmail, Google+ and YouTube accounts 22,000 Twitter accounts

There were thousands of services attacked, there isn't room in the headline for all of them.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#40
post #39
post #31

Ugh. Actually, 410k Facebook, Gmail, and Twitter passwords stolen: 318,000 Facebook accounts 70,000 Gmail, Google+ and YouTube accounts 22,000 Twitter accounts

There were thousands of services attacked, there isn't room in the headline for all of them.

Sure there is: "Two million Facebook, Gmail, other passwords stolen".

Or: "Two million passwords stolen, including from Facebook, Gmail, and Twitter".

Post reply on HN