Live data from Hacker News

Billions of login credentials have been leaked online

apnews.com

11–20 of 65 posts

Re: Billions of login credentials have been leaked online

#11
post #9

This is a good reminder that forcing people to use an E-mail address as a user ID is a stupid and dangerous policy. Voted down by amateurs who set their Web apps up this way. Killing the messenger won't secure your users' credentials.

As if users wouldn't just use the same username everywhere. So now besides telling them to use different passwords for every website, you also need to tell them to use different usernames.

But you can't use the same username everywhere, for example doing a Google search of my username shows accounts on other sites that are not related to me. Doing a search for your username suggests that it is also likely taken on numerous other sites, including a rock-band named FoxyGen that I'm fairly confident you are not a member of.

Re: Billions of login credentials have been leaked online

#13
post #6
post #3

> Sixteen billion is roughly double the amount of people on Earth today, signaling that impacted consumers may have had credentials for more than one account leaked Interesting use as "may have" as that would imply, mathematically speaking, that there are people who were impacted at least twice...

To be fair, we really have no idea how many people are on Earth today. Eight billion is our best estimate, but we also recognize that many of the sources used are undercounted to some degree. What's hard to determine to what degree that might be. A somewhat recent article in Popular Mechanics [ https://www.popularmechanics.com/science/environment/a642223... ] suggests that recent data may indicate that the estimates…

A co-author of the study you refer to was recently on the UK BBC podcast More or Less, debunking much of the press coverage of his study, specifically the headline of vast global underestimation. Rather, the study found rural distribution estimates may be inaccurate, not total population.

Link to the 9 minute episode https://www.bbc.co.uk/programmes/p0lgv5vf

Re: Billions of login credentials have been leaked online

#14

This is a good reminder that forcing people to use an E-mail address as a user ID is a stupid and dangerous policy. Voted down by amateurs who set their Web apps up this way. Killing the messenger won't secure your users' credentials.

The email acts as an implicit second factor. But in any case security is a losing battle anyway. We should assume everything is compromised in the long term

Re: Billions of login credentials have been leaked online

#15
> According to a report published this week, Cybernews researchers have recently discovered 30 exposed datasets that each contain a vast amount of login information — amounting to a total of 16 billion compromised credentials. That includes user passwords for a range of popular platforms including Google, Facebook and Apple.

Can someone more knowledgeable than me explain how my passwords could have been leaked from Google or Apple? Or is this just bad reporting?

It is my understanding that neither Google nor Apple have my passwords stored, and any password service they have like the iCloud keychain would presumably be encrypted. What am I missing?

Re: Billions of login credentials have been leaked online

#17

the article mentioned passkeys as a solution but imho is only a path towards vendor lock-in. Like, "we solve your security issue provided you do business only with us". That is neither "antifragile" nor resilient. It's just hype.

How?

Re: Billions of login credentials have been leaked online

#18

> According to a report published this week, Cybernews researchers have recently discovered 30 exposed datasets that each contain a vast amount of login information — amounting to a total of 16 billion compromised credentials. That includes user passwords for a range of popular platforms including Google, Facebook and Apple. Can someone more knowledgeable than me explain how my passwords could have been leaked from G…

The password to your Google or Apple account?

Re: Billions of login credentials have been leaked online

#19

the article mentioned passkeys as a solution but imho is only a path towards vendor lock-in. Like, "we solve your security issue provided you do business only with us". That is neither "antifragile" nor resilient. It's just hype.

I have my passkeys in 1password and they work fine. One key for each service, I don't see the difference to normal passwords in terms of lock-in

Re: Billions of login credentials have been leaked online

#20

> According to a report published this week, Cybernews researchers have recently discovered 30 exposed datasets that each contain a vast amount of login information — amounting to a total of 16 billion compromised credentials. That includes user passwords for a range of popular platforms including Google, Facebook and Apple. Can someone more knowledgeable than me explain how my passwords could have been leaked from G…

Keyloggers, people reusing passwords
Post reply on HN