Live data from Hacker News

Alleged leak of more than 5M Gmail accounts

isleaked.com

91–100 of 141 posts

Re: Alleged leak of more than 5M Gmail accounts

#91

I can tell from the first 2 characters that the leaked password associated with my email address was scraped from Pizza Hut Australia's online ordering system (they only recently implemented SSL on the login page). It's interesting that I setup a particular password for that service when I noticed it didn't use SSL. Make's me wonder how many databases this comes from. It certainly isn't Google's.

[deleted]

Re: Alleged leak of more than 5M Gmail accounts

#92

Weird, it gives me a very old password. Though back when I had that password my account was hacked. I'd wager this is just Gmail address+password combos collected from other leaks (read: not from Google). Really this just seems to be an attempt at sensationalizing.

I can also verify this. One of my gmail accounts was in there, incidentally the "trash account" I use when I sign up for various services online.

And the password was one of my lowest security "trash passwords" I use with this e-mail as login sometimes if it's a service I wouldn't trust or don't care if it's compromised.

So I wouldn't worry about this. Someone had their site hacked most likely and these are logins to the site, not from Google.

Re: Alleged leak of more than 5M Gmail accounts

#93

Earlier quoted context omitted.

> If what you're concerned about is the idea that Google knows your phone number, you can use Google Authenticator or another TOTP app instead. I'm under the impression that you need to provide Google your phone number before being allowed to enable TOTP.

TOTP algorithm is open, has RFC. Check Google Authenticator Wikipedia page for OSS clients. I guess phone number is needed for the secure reset. In the case you lose the device this would render your account inaccessible.

I do have an OSS client, but the very first step to enable Gmail's 2FA is to give your phone number.

I agree that there are good reasons for asking that, but the comment above apparently raises a good point, namely, that you apparently cannot enable 2FA without giving Google your phone number.

Re: Alleged leak of more than 5M Gmail accounts

#94
post #72

Earlier quoted context omitted.

https://play.google.com/store/apps/details?id=com.google.and...

This is much better: https://play.google.com/store/apps/details?id=com.authy.auth...

This is much better: https://play.google.com/store/apps/details?id=org.fedorahost...

Open source fork of the (now closed source) Google Authenticator.

Re: Alleged leak of more than 5M Gmail accounts

#95
My email is on there, but the password is not the one I'm currently using. Though I wonder which site or sites I've been using this password on. Has anyone figured it out? I'm going to crosscheck with my saved passwords list in Firefox when I get home.

Re: Alleged leak of more than 5M Gmail accounts

#96

If you search for the character '+' in the list of e-mails you can get an idea where the mails leaked from. It seems to me like this is a collection of databases scraped from different sources as others have suggested. For Gmail users, it's a good practice to register to websites using username+websitename@gmail.com (e.g. mark.samman+hackernews@gmail.com), that way you'll know who leaked your data when it appears in…

Going with your suggestion, the amount of DBs must be huge. The most prominent additions after the + sign (ignoring just single numbers) are:

- Bioware (54)

- Bravenet (19)

- Bryce/daz3d/daz (244)

- Eharmony (64)

- Filedropper/fd/etc. (113)

- Freebie/Freebiejeebies (64)

- Friendster (65)

- Hon (42)

- Policeauctions (28)

- Savage/Savage2 (116)

- Xtube/porn (200ish)

Re: Alleged leak of more than 5M Gmail accounts

#98

Earlier quoted context omitted.

If you're worried about giving Google your phone number, you should perhaps also be worried about them having access to all of your email messages.

You should be worried about both of these anyway. I have a couple of old legacy gmail accounts I don't use any more but still keep active, so I have 2FA on them, but anything important goes to my own mail server.

Is this enough, though? Probably to prevent an attacker from stealing your account, but not to stop them from reading your emails.

Do you encrypt your emails? Do you regularly send emails to other people (who probably have Gmail accounts)?

Re: Alleged leak of more than 5M Gmail accounts

#99
The problem with 2FA for me is that I am underground for a good part of my day, without reception.

I use google voice to get notified of calls and voicemails so I can be fairly responsive, but obviously using another service that can be accessed in multiple places defeats the point, especially when owned by the same people.

Re: Alleged leak of more than 5M Gmail accounts

#100
post #12

Links to zip archive with plain email list (without passwords): https://mega.co.nz/#!ewU1wCKA!P52rdL5tMcugRxi8ALyZlGnfE_KSB4... Alternative: http://rghost.net/57937836 The thing is that this site mentions other site where in comments section you can find links to 7zip archive with emails

Thanks! Checking that list against my gmail contacts, I found six of my friends in there!

Did the same, found one.
Post reply on HN