Live data from Hacker News

Alleged leak of more than 5M Gmail accounts

isleaked.com

121–130 of 141 posts

Re: Alleged leak of more than 5M Gmail accounts

#121
post #68

Earlier quoted context omitted.

I don't want 2FA for absolutely everything. I want to authenticate once.

Then your laziness is important to you then your security.

No, as sp332 says, I want something like ssh-agent for the web.

Re: Alleged leak of more than 5M Gmail accounts

#124
post #119

Earlier quoted context omitted.

Yeah, good luck on a windows phone.

Microsoft Authenticator works just fine with GMail :)

Confirmed! Though I had to go outside to get the initial pass code via SMS.

It does not seem like twitter supports this authenticator.

Re: Alleged leak of more than 5M Gmail accounts

#125

Earlier quoted context omitted.

It's a fair point though. At some point you're putting too much of a barrier on everything. You can have security and convenience at the same time, we just haven't done it yet. However, I have 2FA turned on with GMail and I authenticate basically once, then it remembers my PC and I don't have to authenticate again for a long time.

It remembers the second authorization on all your devices?

On my iPhone and my desktop (at home and work).

Re: Alleged leak of more than 5M Gmail accounts

#126
post #35
post #2

Every time something like this is posted, where there is a site to check if your email address is in some leaked list, I really wish they'd just tell me how to get the list itself. Instead, they ask me to trust that they will not use my email address, and I have to hope that they won't leak it. I generally don't bother, because it's just more security risks.

Give me your email, and I'll check for you. I won't do anything, I promise. Joking aside, I downloaded the list and my email is not listed. Phew...

I also checked a few of those near and dear to me. Should probably try my full address list...

Re: Alleged leak of more than 5M Gmail accounts

#127
post #81

Earlier quoted context omitted.

Can you disclose which site?

Can't be sure, it's a "garbage sites" password which I've used too many times on untrusted sites. Any one of those sites could have been hacked, or had been a phishing gateway itself. Of course what I did was bad practice. One should store passwords in a secure password manager, and use a different (preferably 30+ chars) password on each site.

My present "garbage site" practice is to pop open a session to mailinator.com to a randomly generated box name.

Mailinator will give an alternate address that's a hash of the first, so that the address itself cannot be used to check. See below.

I'll create a set of long passwords (20-30 characters) with pwgen. Those are input as name, email, and password fields (different for each). If I need to verify an email, I can.

I don't record the values, they're throwaway.

If the site rejects 'mailinator.com', there are other domains provided as alternates.

Example: inache8baezo0aowahph@mailinator.com is also

    m8r-ds4te4@mailinator.com
    inache8baezo0aowahph@mailinator.com
    inache8baezo0aowahph@mailtothis.com
(or m8r-ds4te4 at the other domains)

The 'm8r' address can't be used to check for mail.

Note, obviously, that anyone with the actual mailbox hash can check it. For example: http://mailinator.com/inbox.jsp?to=facebook

Oh, there's even an RSS mailbox subscription, neat: http://www.mailinator.com/feed?to=

Re: Alleged leak of more than 5M Gmail accounts

#128
post #105

I can tell from the first 2 characters that the leaked password associated with my email address was scraped from Pizza Hut Australia's online ordering system (they only recently implemented SSL on the login page). It's interesting that I setup a particular password for that service when I noticed it didn't use SSL. Make's me wonder how many databases this comes from. It certainly isn't Google's.

Out of interest, do you know from your data as to when your Pizza Hut Australia account could have been compromised? Was it a plus addressing yourname+pizzhut@yourdomain.com type email address? Would be interested to know more about this. I'm @junto on Twitter if you don't mind contacting me. It would be appreciated.

Hi, No I assume that the breach happened in the last 3 years, and before they implemented SSL. I have noticed that http://www.pizzahut.com.au/members/login is still a valid page, inaccessible via SSL, but haven't checked if logging in on that page actually works.

I noticed that they've also implemented a password reset email, instead of their previous practice of just emailing you the password. Hopefully this means that they are no longer keeping unhashed passwords on the system.

It seems that they realised they weren't doing things correctly in the last 6 months (maybe a bit longer, not 100% sure) and have taken steps to rectify this. This may be due to a discovered security breach, but may just be a change in their internal IT policy. Hopefully they're now following best practices!

Re: Alleged leak of more than 5M Gmail accounts

#129
post #81

It isn't the actual Gmail passwords that are leaked. One of my accounts is there, but the password is one I have used on other sites, never on the actual Gmail account.

Can you disclose which site?

it has my ancient password from ~2008 for

http://login.aeriagames.com/user

That company went under 4-5 years ago, and I seem to remember few forum (phpbb afaik) software/database breaches at the time.

Re: Alleged leak of more than 5M Gmail accounts

#130
post #98

Earlier quoted context omitted.

You should be worried about both of these anyway. I have a couple of old legacy gmail accounts I don't use any more but still keep active, so I have 2FA on them, but anything important goes to my own mail server.

Is this enough, though? Probably to prevent an attacker from stealing your account, but not to stop them from reading your emails. Do you encrypt your emails? Do you regularly send emails to other people (who probably have Gmail accounts)?

>Probably to prevent an attacker from stealing your account, but not to stop them from reading your emails.

Since nothing important goes to them any more and I mainly keep them active to stop them getting squatted for for some highly intermittent email (3+yrs) I might have forgotten, then it doesn't matter much there. As it is, the main attacker where gmail is concerned is google itself, followed by the NSA.

As for other people with gmail accounts, yes, but I'm aware of when that happens and wouldn't email anything sensitive to any gmail(hotmail,yahoo,etc.) account.

Post reply on HN