Live data from Hacker News

Alleged leak of more than 5M Gmail accounts

isleaked.com

21–30 of 141 posts

Re: Alleged leak of more than 5M Gmail accounts

#22
For me, it has a password I don't ever recall using with gmail. If I have, I don't think it's been in the past few years.

That said, it's my throwaway password I use on services I'm not particularly worried about. I fear that this isn't a gmail leak but instead a different service.

Re: Alleged leak of more than 5M Gmail accounts

#23
post #6

Earlier quoted context omitted.

Exactly. just show me the list and let me do a command+f. I'm not trying to enter my email into their system.

Are you being serious? Next time you search google, would you rather they display 5,000,000 results on one page and you Ctrl+F the response?

If the local client could handle it, this would be a much more secure way of browsing.

Re: Alleged leak of more than 5M Gmail accounts

#25
post #3

It's nowhere near advisable for anyone to submit their address to that box. Notwithstanding the questionable reliability of this what is meant by "leaked"? a trove of phished credentials does not really qualify as a "leak".

"If you don't like to specify your full email address for any reason, you can replace up to 3 characters with asterisk sign (e.g., for myaccount@gmail.com enter myac*nt@gmail.com), thus we'll show you a count of matches for this pattern. We respect your privacy."

Re: Alleged leak of more than 5M Gmail accounts

#26
post #5
post #2

Every time something like this is posted, where there is a site to check if your email address is in some leaked list, I really wish they'd just tell me how to get the list itself. Instead, they ask me to trust that they will not use my email address, and I have to hope that they won't leak it. I generally don't bother, because it's just more security risks.

"If you don't like to specify your full email address for any reason, you can replace up to 3 characters with asterisk sign (e.g., for myaccount@gmail.com enter myac *nt@gmail.com), thus we'll show you a count of matches for this pattern. We respect your privacy."

Only up to 3 characters? Why 3? Especially since it's an email address and not a random string, which limits the possibilities for the 3 missing characters. This looks like it's giving more info than you'd think to a dodgy website...

Re: Alleged leak of more than 5M Gmail accounts

#28
I just checked using a bunch of throwaway email accounts I had to sign up for various promotions. One of them was leaked - and one of them had a very old password associated with it.

I now use KeePass2 to manage all my passwords - so the old password has absolutely nothing to do with the new one. This makes me think that they simply tried to use some other hacked site, and checked to see whether the same pwd was recycled for gmail.

Re: Alleged leak of more than 5M Gmail accounts

#30

My Gmail was hacked a few years ago. This database showed the first two letters of the password I had at the time. I had (stupidly) been using the same password on other sites, so after I was hacked i made a new password just for gmail. Now I also have two factor authentication :)

[deleted]
Post reply on HN