Live data from Hacker News

The 773M Record “Collection #1” Data Breach

troyhunt.com

101–110 of 128 posts

Re: The 773M Record “Collection #1” Data Breach

#101
Let say my email appeared on Pwned list. And given most ( at least I think most ) people have zillions of web forums, services, sites, services using the email address.

What should you do now? I mean editing and changing password in everyone of them seems like a daunting task. And many of those services I no longer use anyway.

I am thinking of completely giving up the identity and start over, which seems easier. Or any other thoughts and comments?

Edit: I will definitely pay Apple a monthly fee if there is some simple and easy way to have online identity using email along with FaceID or Touch ID as 2FA. Getting rid of password while increasing security is something that should have happened but has yet to happened.

Re: The 773M Record “Collection #1” Data Breach

#103
post #2

Troy won’t store the passwords associated with the username, which is a choice I can absolutely respect. But as he discusses in the post, that leaves users knowing that their email address was in the data dump, but with no way of knowing which site it came from, or what password was breached. So while this increases the number of records in HIBP, and perhaps makes the password popularity tracker a bit more comprehens…

The slightly annoying thing here is that I already use a password manager, so while the impact to me is minimal, I wish I knew which password specifically I have to rotate, instead of assuming that I need to rotate, like, all of them...

I just use diffirent email for each service, so I could identify leaks.

Re: The 773M Record “Collection #1” Data Breach

#104
post #101

Let say my email appeared on Pwned list. And given most ( at least I think most ) people have zillions of web forums, services, sites, services using the email address. What should you do now? I mean editing and changing password in everyone of them seems like a daunting task. And many of those services I no longer use anyway. I am thinking of completely giving up the identity and start over, which seems easier. Or a…

Just use a different e-mail and password for each web site.

Re: The 773M Record “Collection #1” Data Breach

#105
post #96
post #75

Earlier quoted context omitted.

Now I just recommend to people (who don't understand password managers) to use chrome's built-in feature. It's better than using the same password.

I used to think this, but I think this is actually bad advice for a few reasons. 1. People are bad at making new passwords 2. Someone might clear their browser history and delete the logins as a result. 3. Lock-in into the Chrome ecosystem. I personally use KeePass, but I understand it is a bit cumbersome to carry around a USB stick. I'd recommend LastPass to those who don't understand simply because it has a free ti…

Chrome now has a "generate password" option in password fields, and a page where the passwords can be managed.

For the people I'm talking about, installing and maintaining a "real" password manager isn't going to happen. The alternative is for them to continue using "Nameofcat1" for every damn site.

It's a reasonable trade-off.

Re: The 773M Record “Collection #1” Data Breach

#106

Earlier quoted context omitted.

KeePass + Syncthing + YubiKey = Awesome, and free!

Does keepass support yubikey out of the box or is there a certain plugin you use? What do you do about mobile?

KeePassXC supports YubiKey out of the box. I do not access anything important via phone. I usually have my laptop nearby anyway.

Re: The 773M Record “Collection #1” Data Breach

#107
post #87

Earlier quoted context omitted.

I got the same. Anyone here know what is Apollo?

Same here. I had never heard of them. Turns out they're a YC'15 startup ( https://www.apollo.io/company/ ). There are no passwords in the data they lost according to HIBP. They seem to collect personal data from various sources and help other companies increase sales.

So not only do we have to worry about websites we actually use being compromised, but we also have to worry about these sketchy third-party companies that have purchased our data being hacked.

Re: The 773M Record “Collection #1” Data Breach

#108
post #37

Earlier quoted context omitted.

The password itself is not sent. You can read about it here: https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...

He's suggesting using (the link is from your link): https://haveibeenpwned.com/Passwords Which does upload your password, which I think is an unacceptable risk.

> He's suggesting using (the link is from your link): https://haveibeenpwned.com/Passwords

Please don't make false assertions about what I was suggesting without any evidence.

Pwned Passwords consists of a number of tools, which one you choose to use depends on the concerns you have and the effort you choose to put in. Both the API and the SHA download files provide secure means of checking if your password is present in this data dump.

I would certainly not put any live passwords into the webform.

Re: The 773M Record “Collection #1” Data Breach

#109
post #32
post #28

Earlier quoted context omitted.

Why not use Pwned Passwords to check your passwords to see if any of them need to be rotated due to this breach or any other?

Seems really weird to advocate people reveal their passwords to a random untrusted 3rd party. They do have an API that allows you to search for your password based on a truncated checksum, so you can find out if your password was leaked, without revealing the password.

You replies in general have be combative and seeked to push people into positions that you could argue against for internet points.

You could have made your points in a much more constructive and concise manner:

Pwned Passwords is a great data set, I would recommend against using the webform to check your password, instead download the hash file or utilize the extremely simple api. The webform is insecure because...

Re: The 773M Record “Collection #1” Data Breach

#110
post #52

Earlier quoted context omitted.

He has the "Pwned Password" search to allow you to narrow it down and he has a really good article that he links to explaining why despite its inconvenience. If I was him I'd do the same. HIBP is a side project of his and I wouldn't be able to sleep at night knowing I have the responsibility of securing billions of email & password combinations. At the risk of the breach of those accounts adding fuel to the credentia…

I am not sure you should put too much confidence in the "pwned password" search. I know one of the weak password I stupidly reuse everywhere was compromised since I had someone buy something with my paypal account. But it comes up as clean in the password search. So it was probably cracked from one of the leaked hashes but the plain text was never entered into the public dumps.

Well one can't prove a negative, that is that your password _hasn't_ been leaked.

Knowing that - for sure - a password has appeared in a breach is very useful.

Post reply on HN