Live data from Hacker News

773M Password ‘Megabreach’ Is Years Old

krebsonsecurity.com

101–110 of 177 posts

Re: 773M Password ‘Megabreach’ Is Years Old

#101
post #92
post #90

Earlier quoted context omitted.

But how will I guess my email when I do want to reconnect with my account? I see why obfuscation (well, anything to avoid predictability, up to that random hex) is advisable, but the convenience trade-off is real.

If you do that out of memory, you are most likely re-using passwords. Re-using passwords with an easily guessable login isn't a good combination.

> If you do that out of memory, you are most likely re-using passwords.

How does that follow? It still adds value to use aliases that identify the site where they're used, because then you don't need to do a hashtable lookup to see where your mail is coming from.

Re: 773M Password ‘Megabreach’ Is Years Old

#102
post #57

Earlier quoted context omitted.

I think it's interesting that they're trying to get non-technical people who would fall for this kind of thing to buy bitcoins and then send them. Like the number of people who would believe this, have a thousand dollars on hand, and be able to buy and send bitcoins is probably tiny.

Some of the ransomware scammers have actual customer service call centers set up. https://www.reuters.com/article/us-usa-cyber-ransomware-idUS... > Some players in the booming underworld employ graphic artists, call centers and technical support to streamline payment and data recovery, according to security firms that advise businesses on hacking threats.

No surprise. Rule #1 in retail is "Make it easy for the customer to give you their money."

Re: 773M Password ‘Megabreach’ Is Years Old

#103
post #76

Earlier quoted context omitted.

Email a million addresses and you'll wind up hitting a few who've been browsing child porn, or something they'd find highly embarrassing if their parents/spouse/SO found out. As with other scams that can be initiated at scale, you don't need a 50% conversion rate. 0.01% probably suits just fine.

A conversion rate of 0.01% on 700 million addresses and a ~$1000 demand makes you 70million dollar. That's a lot of money for just sending 700 million emails.

Probably a couple orders of magnitude high, too. One in ten thousand? I doubt that many make it through people's spam filters.

Re: 773M Password ‘Megabreach’ Is Years Old

#104
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I got tons of those too, mostly to test accounts. It’s hilarious how bad they are when they use my test names to address me.

Re: 773M Password ‘Megabreach’ Is Years Old

#105
post #88

Anyone here recommend a good security key? Is YubiKey still the best option? I noticed that they don't have any usb-c + NFC options.

They do have NFC and usb-c options (separately, though), and are planning to launch lightning as well

https://www.yubico.com/2019/01/yubico-launches-the-security-...

Re: 773M Password ‘Megabreach’ Is Years Old

#106
post #19

I can't remember if it was haveibeenpwned.com or some other site, but I seem to recall once a few years ago checking my email on a site which also showed you the first two characters of the password which had been compromised. Maybe it has since been discontinued because of security concerns, but I found it really useful at the time because it let me know that the leaked password was an old one that I hadn't used in…

After the Ashley Madison hack, haveibeenpwned still had not instituted blinding so you could check, for example, if your co-workers or boss has an account there, assuming they were follish enough to use their widely-known personal or employer email addresses (the latter being shockingly common for lifer-types st big companies like HP and Cisco).

One of my co-workers ended up getting revealed this way to his then-wife; it wasn’t really a happy marriage up to that point but that was the last straw.

Haveibeenpwned has since gated access to the reports which is good....

Re: 773M Password ‘Megabreach’ Is Years Old

#107
post #51

I think they are also trying to use the same credentials to log in to accounts. I got an email from Epic Game saying there are too many failed login attempts, so it was suspended. Ironically, I don't even remember having one. So I logged into the account and made sure there none of the information on there were personal.

Did you click on the link in the email to log in? That's another one to be aware of, fake clone websites linked to fake emails purporting to be from the company. Always go directly to the site using your bookmarks or typing it in, or at least remember to check the url before you click it.

Actually, they only offered a link for enabling 2FA, And yea, I typed the website in. I have a fake name on the account, and I don't have any payment info on there since I'm not playing any of their games. Now I really have to just think of a constant false name when registering accounts.

Re: 773M Password ‘Megabreach’ Is Years Old

#108
post #33

Probably a good start to using 2FA and security keys.

I think having 2FA should be a feature of every page that provides a login possibility.

There should be a login-as-a-service startup offering secure login tool that is easily configurable.

Re: 773M Password ‘Megabreach’ Is Years Old

#109
post #50
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I've been receiving similar emails for a long time (probably more than a year) with my old Linkedin account password that was part of the 2012 breach. I don't even have a LinkedIn account anymore and I know that I haven't used the password anywhere else since it was randomly generated for that website by my password manager. So I can confirm that scammers seem to leverage password dumps that way. It's quite clever I…

Another data point: I get those to an email that was exclusively used on one insecure message board, but not only with the actual password that I had been using there, but also with a number of comically mangled variations thereof, and with some completely unrelated passwords (not mine). Apparently the data has been compiled from many different sources that went through various stages of bitrot from changing hands repeatedly, possibly with deliberate cutting to inflate numbers.

(oh, and also myspace, some identities are just meant to be stolen I guess...)

Re: 773M Password ‘Megabreach’ Is Years Old

#110
post #28

Earlier quoted context omitted.

The email contains: > You will make the payment by Bi‌tco‌in (if you do not know this, search 'how to buy b‌itcoi‌n' in Google). The top result is from coinbase [1]. I would say everyone capable of online banking is capable of following these steps. [1] https://www.coinbase.com/buy-bitcoin

Wonder if it would be a good idea for coinbase to mention the possibility of you being scammed...

My local grocery store has a sign above the gift cards reminding people that government entities and utility companies will never ask for payment in gift cards. If they can manage a warning, I would hope Bitcoin sites could have a disclaimer somewhere...
Post reply on HN