Live data from Hacker News

Alleged leak of more than 5M Gmail accounts

isleaked.com

71–80 of 141 posts

Re: Alleged leak of more than 5M Gmail accounts

#71
post #26
post #5

Earlier quoted context omitted.

"If you don't like to specify your full email address for any reason, you can replace up to 3 characters with asterisk sign (e.g., for myaccount@gmail.com enter myac *nt@gmail.com), thus we'll show you a count of matches for this pattern. We respect your privacy."

Only up to 3 characters? Why 3? Especially since it's an email address and not a random string, which limits the possibilities for the 3 missing characters. This looks like it's giving more info than you'd think to a dodgy website...

maybe because they want to limit the search time?

Re: Alleged leak of more than 5M Gmail accounts

#72

Earlier quoted context omitted.

With two-factor authentication you are happily providing gmail with your phone number. They say they need this to send you a verification code when you log into your gmail account. Then they say: "During sign-in, you can tell us not to ask for a code again on that particular computer." Well, if that's the trick, they don't need your phone nr at all, they can do ip and os check anyways..

https://play.google.com/store/apps/details?id=com.google.and...

This is much better: https://play.google.com/store/apps/details?id=com.authy.auth...

Re: Alleged leak of more than 5M Gmail accounts

#73
post #56

A summary about phishing: 1. Found you password with the same email address somewhere and ask if you still use that email address on another site. 2. And get your IP, then login through proxy to bypass the security checking. 3. Still, to know which email address is in use. If you just worry, change you password right now without using their service. :P It may be good that every a few months some guys remind you to ch…

Exactly what proxy would allow to appear to be using my IP address?

Re: Alleged leak of more than 5M Gmail accounts

#74

Earlier quoted context omitted.

With two-factor authentication you are happily providing gmail with your phone number. They say they need this to send you a verification code when you log into your gmail account. Then they say: "During sign-in, you can tell us not to ask for a code again on that particular computer." Well, if that's the trick, they don't need your phone nr at all, they can do ip and os check anyways..

If you're worried about giving Google your phone number, you should perhaps also be worried about them having access to all of your email messages.

You should be worried about both of these anyway.

I have a couple of old legacy gmail accounts I don't use any more but still keep active, so I have 2FA on them, but anything important goes to my own mail server.

Re: Alleged leak of more than 5M Gmail accounts

#75
post #12

Links to zip archive with plain email list (without passwords): https://mega.co.nz/#!ewU1wCKA!P52rdL5tMcugRxi8ALyZlGnfE_KSB4... Alternative: http://rghost.net/57937836 The thing is that this site mentions other site where in comments section you can find links to 7zip archive with emails

I bet there are some people who have other leaked account & password lists, and since the isleaked.com site is kind enough to give the first two characters of the password for any given email account, it'd probably be possible to guess the passwords for some of those accounts.

Am I blind? I only see if there is a match, no password initial letters at all ???

EDIT: Not blind, it just doesn't show the initial letters if you search using a wildcard even if there is only 1 match.

Re: Alleged leak of more than 5M Gmail accounts

#76
post #12

Links to zip archive with plain email list (without passwords): https://mega.co.nz/#!ewU1wCKA!P52rdL5tMcugRxi8ALyZlGnfE_KSB4... Alternative: http://rghost.net/57937836 The thing is that this site mentions other site where in comments section you can find links to 7zip archive with emails

OK, my address was in there. I've changed my password. But, how do I know if they actually had my correct password? Shit this is scary...

Assuming hacker did sign in into your Gmail , you might be able to get that information from the list of last logins in your Gmail account. Any IP that's out of your normal location would reveal that. More in this link https://support.google.com/mail/answer/45938?hl=en

Re: Alleged leak of more than 5M Gmail accounts

#77
My account was compromised a couple months ago. Google detected a series of logins from Poland, Lithuania and Oregon (probably botnets, which I think it rejected) and sent me a warning.

I expected my address to be there but it wasn't. Makes me wonder.

Re: Alleged leak of more than 5M Gmail accounts

#78

Earlier quoted context omitted.

OK, my address was in there. I've changed my password. But, how do I know if they actually had my correct password? Shit this is scary...

Assuming hacker did sign in into your Gmail , you might be able to get that information from the list of last logins in your Gmail account. Any IP that's out of your normal location would reveal that. More in this link https://support.google.com/mail/answer/45938?hl=en

Yeah, this is an account that only forwards emails, so I almost never log in. However, when I changed my password now I logged in and out a bunch of times. This made this very short list of recently logged locations only contain one line that was not from today. Hmm. Would be better if they showed 50 recent logins or something...

Re: Alleged leak of more than 5M Gmail accounts

#80
post #51

Earlier quoted context omitted.

I'm not sure exactly what point you're trying to make, but you seem confused about how 2FA works. The goal of 2FA/MFA is to make you demonstrate that you're in possession of two independent secrets (authentication factors). Once you've shown that, it's considered safe enough to replace the second secret (OTP sent to your phone or generated by your TOTP app like Google Authenticator) with a cookie (the check is not IP…

> If what you're concerned about is the idea that Google knows your phone number, you can use Google Authenticator or another TOTP app instead. I'm under the impression that you need to provide Google your phone number before being allowed to enable TOTP.

TOTP algorithm is open, has RFC. Check Google Authenticator Wikipedia page for OSS clients.

I guess phone number is needed for the secure reset. In the case you lose the device this would render your account inaccessible.

Post reply on HN