Live data from Hacker News

Alleged leak of more than 5M Gmail accounts

isleaked.com

101–110 of 141 posts

Re: Alleged leak of more than 5M Gmail accounts

#101
post #68
post #32

Now is a good time to enable two-factor authentication on your accounts. Here is how to do so for some common services: - Google: https://www.google.com/landing/2step/ - Github: https://github.com/settings/security - AWS: http://aws.amazon.com/mfa/virtual_mfa_applications - Facebook: https://www.facebook.com/settings?tab=security - Twitter: https://twitter.com/settings/security - Dropbox: https://www.dropbox.com/acco…

I don't want 2FA for absolutely everything. I want to authenticate once.

Then your laziness is important to you then your security.

Re: Alleged leak of more than 5M Gmail accounts

#103
post #99

The problem with 2FA for me is that I am underground for a good part of my day, without reception. I use google voice to get notified of calls and voicemails so I can be fairly responsive, but obviously using another service that can be accessed in multiple places defeats the point, especially when owned by the same people.

You don't need reception for 2FA; Google Authenticator and FreeOTP work fine even in airplane mode, if you have your phone / tablet with you.

Re: Alleged leak of more than 5M Gmail accounts

#104

The passwords seem to have come from somewhere else. My email is on the list, but the password is wrong and actually matches the one I use for throwaway accounts.

There seem to be enough people reporting this to do some correlation and figure out what was really compromised.

Re: Alleged leak of more than 5M Gmail accounts

#105

I can tell from the first 2 characters that the leaked password associated with my email address was scraped from Pizza Hut Australia's online ordering system (they only recently implemented SSL on the login page). It's interesting that I setup a particular password for that service when I noticed it didn't use SSL. Make's me wonder how many databases this comes from. It certainly isn't Google's.

Out of interest, do you know from your data as to when your Pizza Hut Australia account could have been compromised? Was it a plus addressing yourname+pizzhut@yourdomain.com type email address?

Would be interested to know more about this. I'm @junto on Twitter if you don't mind contacting me. It would be appreciated.

Re: Alleged leak of more than 5M Gmail accounts

#106

If you search for the character '+' in the list of e-mails you can get an idea where the mails leaked from. It seems to me like this is a collection of databases scraped from different sources as others have suggested. For Gmail users, it's a good practice to register to websites using username+websitename@gmail.com (e.g. mark.samman+hackernews@gmail.com), that way you'll know who leaked your data when it appears in…

On the other hand, this will reveal to anyone you have a HN/NRA/porn account in case of a leak ;)

Re: Alleged leak of more than 5M Gmail accounts

#107
post #56

A summary about phishing: 1. Found you password with the same email address somewhere and ask if you still use that email address on another site. 2. And get your IP, then login through proxy to bypass the security checking. 3. Still, to know which email address is in use. If you just worry, change you password right now without using their service. :P It may be good that every a few months some guys remind you to ch…

Exactly what proxy would allow to appear to be using my IP address?

For many security checks, a proxy in the same country would be sufficient. They might only check if you log in from Asia and America at the same time.

Re: Alleged leak of more than 5M Gmail accounts

#108
post #68

Earlier quoted context omitted.

I don't want 2FA for absolutely everything. I want to authenticate once.

Then your laziness is important to you then your security.

It's a fair point though. At some point you're putting too much of a barrier on everything. You can have security and convenience at the same time, we just haven't done it yet.

However, I have 2FA turned on with GMail and I authenticate basically once, then it remembers my PC and I don't have to authenticate again for a long time.

Re: Alleged leak of more than 5M Gmail accounts

#109
post #99

The problem with 2FA for me is that I am underground for a good part of my day, without reception. I use google voice to get notified of calls and voicemails so I can be fairly responsive, but obviously using another service that can be accessed in multiple places defeats the point, especially when owned by the same people.

You don't need reception for 2FA; Google Authenticator and FreeOTP work fine even in airplane mode, if you have your phone / tablet with you.

Yeah, good luck on a windows phone.

Re: Alleged leak of more than 5M Gmail accounts

#110
post #68

Earlier quoted context omitted.

I don't want 2FA for absolutely everything. I want to authenticate once.

Then your laziness is important to you then your security.

I have ssh-agent for SSH. Can we get something similar for websites?
Post reply on HN