Live data from Hacker News

773M Password ‘Megabreach’ Is Years Old

krebsonsecurity.com

1–10 of 177 posts

Re: 773M Password ‘Megabreach’ Is Years Old

#2
All of the breaches are, especially these compilation ones. I switched email addresses back in 2016, and despite having accounts basically everywhere, my newer account has never showed up in a breach. Even the email address I used primarily for new accounts years before that hasn't shown up in any. Only my original created-in-2006 Gmail account ends up in breach lists.

Re: 773M Password ‘Megabreach’ Is Years Old

#4

All of the breaches are, especially these compilation ones. I switched email addresses back in 2016, and despite having accounts basically everywhere, my newer account has never showed up in a breach. Even the email address I used primarily for new accounts years before that hasn't shown up in any. Only my original created-in-2006 Gmail account ends up in breach lists.

On the topic of old email addresses, make sure your old email provider doesn't release your email address after so many years / months. This is a common way to get access to accounts by creating a new email account with the same address as an expired address and then using an email-based password reset to gain access to the account. Happened to my wife with an old email address from high school.

Re: 773M Password ‘Megabreach’ Is Years Old

#5
post #4

All of the breaches are, especially these compilation ones. I switched email addresses back in 2016, and despite having accounts basically everywhere, my newer account has never showed up in a breach. Even the email address I used primarily for new accounts years before that hasn't shown up in any. Only my original created-in-2006 Gmail account ends up in breach lists.

On the topic of old email addresses, make sure your old email provider doesn't release your email address after so many years / months. This is a common way to get access to accounts by creating a new email account with the same address as an expired address and then using an email-based password reset to gain access to the account. Happened to my wife with an old email address from high school.

My understanding is that as of now, Google never permits account name reuse. That being said, I keep all of my old accounts, even if I don't use them anymore. I do check Gmail occasionally for emails which trickle in from time to time.

Re: 773M Password ‘Megabreach’ Is Years Old

#6
So the seller shows a screenshot with browser tabs, a date and a time. One of the tabs is really very specific, looking at a particular disqus profile.

I'm not familiar with Windows; is there anything in the screenshot to suggest its torbrowser or anything like that?

Presumably the miscreant's ISP and e.g. the Russian government can guess real easy whom generated that screenshot...?

Of course what they'd do with that info is anyone's guess. It could well not be an offence to sell collections of passwords, if in deed its even an offence to hack those passwords in the first place.

Re: 773M Password ‘Megabreach’ Is Years Old

#7
post #3

Thank goodness everyone changes their password regularly.

In all seriousness, the reason why this and several collections roughly as large as it went for $45 on the market is precisely that it must not be that useful anymore. If it truly were a skeleton key to the world it would not be going for $45.

I'm abundantly positive there's still a lot of perfectly valid login credentials in there, but the trick is finding them without also triggering rate limiting detection now.

Re: 773M Password ‘Megabreach’ Is Years Old

#9
post #7
post #3

Thank goodness everyone changes their password regularly.

In all seriousness, the reason why this and several collections roughly as large as it went for $45 on the market is precisely that it must not be that useful anymore. If it truly were a skeleton key to the world it would not be going for $45. I'm abundantly positive there's still a lot of perfectly valid login credentials in there, but the trick is finding them without also triggering rate limiting detection now.

I'm not aware of the specifics of the dark market, but from a marketing perspective selling something for cheap makes it easier to sell volume. Perhaps the guy who did the hack didn't want to go into the trouble of finding the one bidder who would give him top dollars, not to mention the dangers a contact like that might include. It's easier to find 1k buyers for $45 than one for $45k.

Re: 773M Password ‘Megabreach’ Is Years Old

#10

So the seller shows a screenshot with browser tabs, a date and a time. One of the tabs is really very specific, looking at a particular disqus profile. I'm not familiar with Windows; is there anything in the screenshot to suggest its torbrowser or anything like that? Presumably the miscreant's ISP and e.g. the Russian government can guess real easy whom generated that screenshot...? Of course what they'd do with that…

That looks like a regular version of Chrome running on Windows 7. But it could be running on a proxy or a VPN.
Post reply on HN