Live data from Hacker News

Two million Facebook, Gmail and Twitter passwords stolen

money.cnn.com

71–80 of 107 posts

Re: Two million Facebook, Gmail and Twitter passwords stolen

#73

Earlier quoted context omitted.

What good will that do against a keylogger?

Strength of password won't really help for key logging, but using e.g. Lastpass helps because it logs you into everything without having to type your passwords. It will even generate and fill in your initial passwords so that you never have to type your passwords even once.

Lastpass doesn't have a password itself?

Re: Two million Facebook, Gmail and Twitter passwords stolen

#74
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

2FA will make password managers obsolete.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#75
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

In addition, for those using a Windows PC in a remote location (such as travelling and visiting an internet cafe) a simple step you can take to help avoid this issue is to use the on-screen keyboard. It's available as an accessibility option, but you can also open it using "Windows Key + R", and then type "osk"

Of course, you should take care to shield your screen while you type the password, or use a combination of mouse+keyboard when entering it.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#76

Misleading headline, makes it seem like these guys were hacked on their servers. When the reality is people spread a virus and passwords were logged from individual machines. No fault from Google or Twitter.

Yup. They're talking about the recent spiderlabs report it seems.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#77

Misleading headline, makes it seem like these guys were hacked on their servers. When the reality is people spread a virus and passwords were logged from individual machines. No fault from Google or Twitter.

Yup. They're talking about the recent spiderlabs report it seems.

The source is this SpiderLabs blog post:

http://blog.spiderlabs.com/2013/12/look-what-i-found-moar-po...

Re: Two million Facebook, Gmail and Twitter passwords stolen

#79
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I gave up on Google yesterday, when I tried to log-in to my account, from home, with the correct username and password, and they decided to lock me out. They said it was a 'new location', and to recover, I needed to know the answer to my 5 year old security question. That wasn't possible, so the other option was entering the month my account was created. The month? I can narrow it down to a 3 year window at best. Needless to say, recovery failed, and I can no longer access my account, because Google just decided I'm not me.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#80
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I gave up on Google yesterday, when I tried to log-in to my account, from home, with the correct username and password, and they decided to lock me out. They said it was a 'new location', and to recover, I needed to know the answer to my 5 year old security question. That wasn't possible, so the other option was entering the month my account was created. The month? I can narrow it down to a 3 year window at best. Nee…

Another lesson people need to learn is to keep their security information up to date! Google (and others) periodically prompt you to do this. I suppose it gets treated much like regularly changing your password though..

Saying that, I'm sorry to hear you got locked out! How inconvenient.

Post reply on HN