Live data from Hacker News

Two million Facebook, Gmail and Twitter passwords stolen

money.cnn.com

61–70 of 107 posts

Re: Two million Facebook, Gmail and Twitter passwords stolen

#63
If you use LastPass, this is a good time to run their Security Challenge (https://lastpass.com/index.php?securitychallenge=1) to audit the strength and uniqueness of your passwords. If you're not using LassPass or something similar like 1Password then today is a good time to fix that.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#64
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

Certainly a good - and probably the best - option right now.

But maybe there are simpler alternatives. Maybe passwords shoudn't mean anything, just like losing a key on a busy street is not exactly a security threat to its owner, password leaks shouldn't be harmful. Maybe the problem is not how passwords are stored or encrypted but how meaninful our 'ids' are - and how they are attached to that password.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#65
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I'm with you on 2 factor auth, but I'm not sure about the password manager. I've always felt like putting all your passwords in one place defeats the purpose of memorizing separate, secure passwords (or, better yet, pass phrases).

The purpose of memorizing the passwords is a) so you always have access to them b) so they are safe

The idea is that password managers should meet both these goals as well.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#66
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

[deleted]

Re: Two million Facebook, Gmail and Twitter passwords stolen

#67

If you use LastPass, this is a good time to run their Security Challenge ( https://lastpass.com/index.php?securitychallenge=1 ) to audit the strength and uniqueness of your passwords. If you're not using LassPass or something similar like 1Password then today is a good time to fix that.

What good will that do against a keylogger?

Re: Two million Facebook, Gmail and Twitter passwords stolen

#68
post #54

"File Transfer Protocol (FTP, the standard network used when working from home) " May be at CNN, that is what they use to work from home.

HN greatly overestimates how dead FTP is.

yeah because we had scp and rsync. Hell even dropbox.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#69

If you use LastPass, this is a good time to run their Security Challenge ( https://lastpass.com/index.php?securitychallenge=1 ) to audit the strength and uniqueness of your passwords. If you're not using LassPass or something similar like 1Password then today is a good time to fix that.

What good will that do against a keylogger?

Strength of password won't really help for key logging, but using e.g. Lastpass helps because it logs you into everything without having to type your passwords. It will even generate and fill in your initial passwords so that you never have to type your passwords even once.
Post reply on HN