Live data from Hacker News

Two million Facebook, Gmail and Twitter passwords stolen

money.cnn.com

51–60 of 107 posts

Re: Two million Facebook, Gmail and Twitter passwords stolen

#51
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

Agreed. 2FA is still rare enough that if a service you use offers 2FA, that's a sign you should probably use it.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#52
post #44

Earlier quoted context omitted.

I'm with you on 2 factor auth, but I'm not sure about the password manager. I've always felt like putting all your passwords in one place defeats the purpose of memorizing separate, secure passwords (or, better yet, pass phrases).

The purpose of separate, secure passwords is because otherwise all it takes is 1 website out there to be insecure to compromise all your logins. If your computer is compromised you already lost, regardless of whether you use a password manager or not.

If a person accesses your phone or laptop, he or she will not necessarily have access to all your credentials for various services and for other devices. But if all this info is stored in one place, in a password manager, the scope of the potential data breach suddenly grows.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#55
post #35

Earlier quoted context omitted.

The ADP -- a payroll service -- passwords (which, interestingly, aren't in the headline), are probably the ones that, despite being smallest in number, offer the most opportunity for direct financial disruption.

ADP is horrible, but their website can't change financial details (it only shows paystubs and tax forms). You can kinda change things through ADP FlexDirect, but all direct deposit enrollment is done elsewhere. The ADP employee site hasn't changed in the past ten years and still uses basic auth. It's horrible. And freaky. When you login to your new company account, it shows all paystubs from your past employers too.…

> ADP is horrible, but their website can't change financial details

The article here says that the account information that was compromised can. I'm not sure if that is a result of bad reporting on the same level as that related to FTP in the article, or the accounts that were compromised are different than the ones for the website you are talking about.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#56
post #35

Earlier quoted context omitted.

ADP is horrible, but their website can't change financial details (it only shows paystubs and tax forms). You can kinda change things through ADP FlexDirect, but all direct deposit enrollment is done elsewhere. The ADP employee site hasn't changed in the past ten years and still uses basic auth. It's horrible. And freaky. When you login to your new company account, it shows all paystubs from your past employers too.…

> ADP is horrible, but their website can't change financial details The article here says that the account information that was compromised can. I'm not sure if that is a result of bad reporting on the same level as that related to FTP in the article, or the accounts that were compromised are different than the ones for the website you are talking about.

Yeah, it's possible they were HR-level accounts that actually run payroll and not just employee accounts.

The more power you wield in an organization the less competent with technology you are.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#57

"File Transfer Protocol (FTP, the standard network used when working from home) " May be at CNN, that is what they use to work from home.

Looks like they updated the article to read "File Transfer Protocol (FTP, the standard network used when transferring big files)". Better, although it's still wrong to call FTP a "network".

Re: Two million Facebook, Gmail and Twitter passwords stolen

#58
post #56

Earlier quoted context omitted.

> ADP is horrible, but their website can't change financial details The article here says that the account information that was compromised can. I'm not sure if that is a result of bad reporting on the same level as that related to FTP in the article, or the accounts that were compromised are different than the ones for the website you are talking about.

Yeah, it's possible they were HR-level accounts that actually run payroll and not just employee accounts. The more power you wield in an organization the less competent with technology you are.

That's probably only even roughly true in tech organizations where the low-level folk have tech-related duties. (Though HN users are probably somewhat biased to think in terms of such organizations.)

Re: Two million Facebook, Gmail and Twitter passwords stolen

#59
post #44

Earlier quoted context omitted.

The purpose of separate, secure passwords is because otherwise all it takes is 1 website out there to be insecure to compromise all your logins. If your computer is compromised you already lost, regardless of whether you use a password manager or not.

If a person accesses your phone or laptop, he or she will not necessarily have access to all your credentials for various services and for other devices. But if all this info is stored in one place, in a password manager, the scope of the potential data breach suddenly grows.

They don't suddenly have access, if your password manager is secure and your master password is strong.

That's one of the nice things about password managers. You reduce the number of potential points of failure from many to one. Why is this good? Think of Thermopylae. You increase the stakes, but you also dramatically improve your ability to fight back.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#60
post #54

"File Transfer Protocol (FTP, the standard network used when working from home) " May be at CNN, that is what they use to work from home.

HN greatly overestimates how dead FTP is.

But I heard FTP was declared harmful and phased out in 1970?
Post reply on HN