Live data from Hacker News

Two million Facebook, Gmail and Twitter passwords stolen

money.cnn.com

81–90 of 107 posts

Re: Two million Facebook, Gmail and Twitter passwords stolen

#83

Which operating systems were affected? It seems like the official report doesn't even contain this critical information.

Windows XP/2003/Vista/7/8 (x32/x64)

Apparently this keylogger was used:

http://malware.dontneedcoffee.com/2013/10/jolly-roger-steale...

Re: Two million Facebook, Gmail and Twitter passwords stolen

#84

What platform(s) was the keylogger written for and how was it spread?

Windows XP/2003/Vista/7/8 (x32/x64) Apparently this one: http://malware.dontneedcoffee.com/2013/10/jolly-roger-steale...

This makes me wonder, would running WireShark at all times provide some protection from viruses by spooking them?

Re: Two million Facebook, Gmail and Twitter passwords stolen

#85
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

Facebook just gave a talk at an HN London meetup recently about exactly this topic: http://vimeo.com/80460475#t=11m48s . The gist is that 2FA doesn't work because people don't enable it, but you can protect accounts by detecting anomalous behaviour on logins.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#86
post #80

Earlier quoted context omitted.

I gave up on Google yesterday, when I tried to log-in to my account, from home, with the correct username and password, and they decided to lock me out. They said it was a 'new location', and to recover, I needed to know the answer to my 5 year old security question. That wasn't possible, so the other option was entering the month my account was created. The month? I can narrow it down to a 3 year window at best. Nee…

Another lesson people need to learn is to keep their security information up to date! Google (and others) periodically prompt you to do this. I suppose it gets treated much like regularly changing your password though.. Saying that, I'm sorry to hear you got locked out! How inconvenient.

I have my passwords secure, and use Keepass. The database is backed up on my Truecrypt external drives, in case my laptop is stolen, and I lose the database file.

I figure my job is to protect my username and password, so that's exactly what I do, secure them, and have backups. What I don't expect is getting locked out of my account when I have the valid username and password to login. Also, Google provides zero support. I generate them at least $20k a year in profits off advertising, and I lose my Gmail account for no reason. Anyway, I'm done with them, and switching to alternatives.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#87

Earlier quoted context omitted.

Strength of password won't really help for key logging, but using e.g. Lastpass helps because it logs you into everything without having to type your passwords. It will even generate and fill in your initial passwords so that you never have to type your passwords even once.

Lastpass doesn't have a password itself?

Ah great question. It does, but it usually stays logged in on your computer, since it runs locally. So you rarely if ever need to type your password for Lastpass, meaning the keylogger would have had to be running on your computer when you installed and set up Lastpass. On a related note, it can also be set up with 2 factor auth.

Re: Two million Facebook, Gmail and Twitter passwords stolen

#88
post #8

2 Factor Authentication, 2 Factor Authentication, 2 Factor Authentication! I've had 2 factor authentication enabled on my gmail account for over a year now, and once you get past the initial setup phase, it's really not that inconvenient. I have even been able to train my parents to use 2 factor auth, I just need to get them using a password manager now...

I've been on 2-factor auth for a while, but only switched to a password manager after my "default" password got hacked in that Adobe incident some weeks back. (KeePassX!)

Re: Two million Facebook, Gmail and Twitter passwords stolen

#90

Earlier quoted context omitted.

Lastpass doesn't have a password itself?

Ah great question. It does, but it usually stays logged in on your computer, since it runs locally. So you rarely if ever need to type your password for Lastpass, meaning the keylogger would have had to be running on your computer when you installed and set up Lastpass. On a related note, it can also be set up with 2 factor auth.

Presumably the password is stored to a file or in memory (of course that could be arbitrarily difficult to figure out how to decode, but it can't be encrypted since that would require another password.)
Post reply on HN