Live data from Hacker News

773M Password ‘Megabreach’ Is Years Old

krebsonsecurity.com

111–120 of 177 posts

Re: 773M Password ‘Megabreach’ Is Years Old

#111
post #19

I can't remember if it was haveibeenpwned.com or some other site, but I seem to recall once a few years ago checking my email on a site which also showed you the first two characters of the password which had been compromised. Maybe it has since been discontinued because of security concerns, but I found it really useful at the time because it let me know that the leaked password was an old one that I hadn't used in…

haveibeenpwned has an api to check your password against their known list that only requires to send the first 5 characters of the sha-1 hash: https://api.pwnedpasswords.com/range/5407a . You get a list of corresponding hash suffixes and check if yours is there. https://haveibeenpwned.com/api/v2/#SearchingPwnedPasswordsBy...

That interactive javascript checker on their site also uses that API, so in theory HIBP doesn't get sent a copy of your password.

A couple of weeks ago I spun up a little clone with slightly-simpler javascript, just in case HIBP starts serving malicious javascript: https://safepasswordchecker.hashbase.io/

Feel free to download the site and javascript for a static copy. Or reuse or modify and reshare as you like, as long as you're not malicious.

Edit: This site was made with Beaker Browser (https://beakerbrowser.com), which is rad, and you should check it out. Feel free to download / fork this site.

Re: 773M Password ‘Megabreach’ Is Years Old

#112
post #46
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

The best defense, just in case one of these cases turns out to be legit, is to send a video of myself watching porn to all my contacts preemptively. Take out their leverage, you know?

Mmm, clever.

Re: 773M Password ‘Megabreach’ Is Years Old

#113

Earlier quoted context omitted.

Unless it's a black mirror twist. Next thing you're following some trolls orders to kill people to conceal your dark secret

yea, umm.... that wasn't regular porn he was watching

Just watched this episode. I didn't take that "revelation" at the end to mean he actually did that. Saw it as just the final "lulz" move in the trolling.

As an embellishment by the trolls, it would probably move any authority figures from a position of "let's figure out who got this dumb kid mixed up in these terrible things" to stony indifference and something closer to "serves him right." It also alienates him from his family so he has nobody in his corner any more.

Consider your own reaction as a viewer. Think about the other person who was involved in the last task of the episode. Did you feel any sympathy for him?

Re: 773M Password ‘Megabreach’ Is Years Old

#114
post #19

I can't remember if it was haveibeenpwned.com or some other site, but I seem to recall once a few years ago checking my email on a site which also showed you the first two characters of the password which had been compromised. Maybe it has since been discontinued because of security concerns, but I found it really useful at the time because it let me know that the leaked password was an old one that I hadn't used in…

haveibeenpwned has an api to check your password against their known list that only requires to send the first 5 characters of the sha-1 hash: https://api.pwnedpasswords.com/range/5407a . You get a list of corresponding hash suffixes and check if yours is there. https://haveibeenpwned.com/api/v2/#SearchingPwnedPasswordsBy...

I did the offline check yesterday and wrote up how to do it: https://stackoverflow.com/q/54249403/96588

Re: 773M Password ‘Megabreach’ Is Years Old

#115
This has been the event that has finally convinced my wife to use a password manager. I'm torn between bitwarden and 1Password though. Anyone care to weigh in on the options? My biggest concern with BitWarden is the lack of automated testing

edit - just fyi, Bitwarden responded on github last month with a plan to add some testing, and I think some of their code does use automated testing. They have issues on GitHub tracking it :)

Re: 773M Password ‘Megabreach’ Is Years Old

#116

This has been the event that has finally convinced my wife to use a password manager. I'm torn between bitwarden and 1Password though. Anyone care to weigh in on the options? My biggest concern with BitWarden is the lack of automated testing edit - just fyi, Bitwarden responded on github last month with a plan to add some testing, and I think some of their code does use automated testing. They have issues on GitHub t…

Bitwarden is nice from a user perspective. I'm a former 1password user and switched because I felt that things in the 1password world moved slowly, even though it costs more than Bitwarden. Bitwarden being open source and audited also helps a lot for trusting it, even if it isn't perfect.

1password has a rock solid UX that looks pretty. Bitwarden is more practical imo. I prefer the latter these days. Guessing the 1password iOS app is probably better than what Bitwarden offers, but I don't know, because I use an Android phone, and I prefer Bitwarden on Android.

Re: 773M Password ‘Megabreach’ Is Years Old

#117
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

> recorded watching porn What a damning position to be in, in 2019.

I think among younger people watching porn is a given. It's ubiquitous, especially as production of pornographic media has exploded in the last decade. People post their nude selfies online for fun and seem to be fine. I've seen people I know post their photos on their personal Instagrams. At some point there must be diminishing returns for would-be blackmailers.

Re: 773M Password ‘Megabreach’ Is Years Old

#118

This has been the event that has finally convinced my wife to use a password manager. I'm torn between bitwarden and 1Password though. Anyone care to weigh in on the options? My biggest concern with BitWarden is the lack of automated testing edit - just fyi, Bitwarden responded on github last month with a plan to add some testing, and I think some of their code does use automated testing. They have issues on GitHub t…

Why not keepass, I've never had an issue and it works great!

Re: 773M Password ‘Megabreach’ Is Years Old

#119
post #74

Earlier quoted context omitted.

If you're using a password manager to randomly generate long, secure passwords, the email address shouldn't matter much. The only potential issue would be social engineering to gain access to the account, but seeing how most people use the same email everywhere, I would think you'd have to a potential target for that to be of concern.

There are good reasons to provide unique aliases to companies requesting an email: - if they start sending you spam you can severe their capacity to contact you by deleting the alias - if they give your contact to a third party, you know from the alias who leaked your email address - if you see an email on a data breach like this one, you know immediately which website got hacked - it makes it really hard to correlat…

I don't disagree with providing unique emails to various services, I just don't think that _randomstring_@your-domain.com is better than myspace@your-domain.com than. I actually think it's worse, since it's more difficult to identify when an email is coming from the wrong place. If I get an email to myspace@domain.com and it's not from MySpace, I know right away. That's not as immediately obvious if I get an email to a random string.

Re: 773M Password ‘Megabreach’ Is Years Old

#120
post #116

This has been the event that has finally convinced my wife to use a password manager. I'm torn between bitwarden and 1Password though. Anyone care to weigh in on the options? My biggest concern with BitWarden is the lack of automated testing edit - just fyi, Bitwarden responded on github last month with a plan to add some testing, and I think some of their code does use automated testing. They have issues on GitHub t…

Bitwarden is nice from a user perspective. I'm a former 1password user and switched because I felt that things in the 1password world moved slowly, even though it costs more than Bitwarden. Bitwarden being open source and audited also helps a lot for trusting it, even if it isn't perfect. 1password has a rock solid UX that looks pretty. Bitwarden is more practical imo. I prefer the latter these days. Guessing the 1pa…

I use bitwarden personally and I like it a lot. I was using Dashlane previously and the ubuntu UX was awful (strictly browser extension, missing features, etc).

I'm only nervous about Bitwarden because of the lack of automated testing. Apparently at least one closed-source one apparently does not test either, possibly but please don't quote me on that since my memory is fuzzy.

See my note above about Bitwarden adding tests though

Post reply on HN