Live data from Hacker News

773M Password ‘Megabreach’ Is Years Old

krebsonsecurity.com

141–150 of 177 posts

Re: 773M Password ‘Megabreach’ Is Years Old

#141
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

The bitcoin address is different :), mine is 1Mzpnco6nKkHTRNr9bhMa7JqGt7ABtqLBx and they ask for $943

Re: 773M Password ‘Megabreach’ Is Years Old

#142
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I got a dozen of these mails all from different addresses, each with a different wallet address. I checked each wallet and no transactions were made to those either, so it doesn't seem so fruitful.

Interestingly, I also did play heroes of newerth so I guess that you're right on that notion.

Another fun fact, each time my password was mentioned, it was missing the first letter.

Re: 773M Password ‘Megabreach’ Is Years Old

#143
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I got a dozen of these mails all from different addresses, each with a different wallet address. I checked each wallet and no transactions were made to those either, so it doesn't seem so fruitful. Interestingly, I also did play heroes of newerth so I guess that you're right on that notion. Another fun fact, each time my password was mentioned, it was missing the first letter.

>Another fun fact, each time my password was mentioned, it was missing the first letter.

I get an old password in these kinds of emails that has been stripped of case, the capitalization I used is not what what I received. Still, the first was was attention grabbing, even if I've long moved on from that password to a password manager with a randomly generated password for each site.

Re: 773M Password ‘Megabreach’ Is Years Old

#144
post #73
post #47

Earlier quoted context omitted.

Yea, a double video of you and what you are watching. Select the most degenerate stuff you ever watched. This would be a nightmare for basically anyone.

This reminds me of the time I experimented with screen recording for self-analysis and productivity. It sometimes captured things I didn't want on video, but I forgot to turn off the recorder while I was deleting the footage. So I ended up with footage of me trying to cover up embarrassing footage.

Has anyone done this as part of a ‘presentation skills’ course? You record yourself giving your talk and then you play it back but sped up a little.

Boy do those nervous ticks appear obvious at 2x. By the end you just want to scream out to yourself “stop touching your ear!”.

Re: 773M Password ‘Megabreach’ Is Years Old

#145
post #58

Earlier quoted context omitted.

Wonder if it would be a good idea for coinbase to mention the possibility of you being scammed...

Why? They take a percentage out of everything you transfer, ofc they wouldn’t want to warn you.

That’s a very narrow and cynical view of their business.

It’s as easy to assume that a world in which crypto is a trusted, common method of value transfer benefits them if they’re a leader in that space.

Re: 773M Password ‘Megabreach’ Is Years Old

#146
post #66
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I just got one with nearly the same wording. "I am aware [old password] is your passphrases. Lets get directly to point..." sent from 202.140.33.240 using the spoofed email address oo@r.com. The bitcoin address is different: 1ELzee2T9Wd5YPTYhWbWD3xK7xB5tJ94J4 Looks like the scam worked a couple times so far: https://www.blockchain.com/btc/address/1ELzee2T9Wd5YPTYhWbWD...

I’ve checked into some of these wallets and some of the early ones (I started receiving these several months ago) had $10k-$16k worth in deposits. And then some have none.

Re: 773M Password ‘Megabreach’ Is Years Old

#147

This has been the event that has finally convinced my wife to use a password manager. I'm torn between bitwarden and 1Password though. Anyone care to weigh in on the options? My biggest concern with BitWarden is the lack of automated testing edit - just fyi, Bitwarden responded on github last month with a plan to add some testing, and I think some of their code does use automated testing. They have issues on GitHub t…

If you happen to be on MacOS, keychain works great for me.

Re: 773M Password ‘Megabreach’ Is Years Old

#148
post #74

Earlier quoted context omitted.

There are good reasons to provide unique aliases to companies requesting an email: - if they start sending you spam you can severe their capacity to contact you by deleting the alias - if they give your contact to a third party, you know from the alias who leaked your email address - if you see an email on a data breach like this one, you know immediately which website got hacked - it makes it really hard to correlat…

I don't disagree with providing unique emails to various services, I just don't think that _randomstring_@your-domain.com is better than myspace@your-domain.com than. I actually think it's worse, since it's more difficult to identify when an email is coming from the wrong place. If I get an email to myspace@domain.com and it's not from MySpace, I know right away. That's not as immediately obvious if I get an email to…

[deleted]

Re: 773M Password ‘Megabreach’ Is Years Old

#149
post #38

Earlier quoted context omitted.

Adding a bit of security on the identification side (usernames/emails) isn't completely useless, but the focus should be on securing authentication. I.e. never use a password twice and add 2FA to everything even vaguely important to you. With password managers that's also way easier than managing a lot of email accounts.

I use Bitwarden, password autogen, and 2FA to manage those too, though I'm not fully migrated over yet (still have a lot of weak duplicate passwords). My problem is the older services I have to use that don't support 2FA.

In all honesty, it's probably not worth worrying about. The implementation of 2FA you're referring to here is just adding a 2nd secret, with a small twist of having time component.

There are very few scenarios where your (high entropy) password would be compromised in a way that wouldn't also lead to the discovery of at least 1 functional 2FA code.

1) Website is breached. If they can get the account password hashes, chances are they're going to get the TOTP seeds as well.

2) You're phished. Your attacker passes through your credentials (scraping the password along the way), and they get a functional session token. With most services, you can turn off 2FA just by reconfirming the account password.

3) Your password manager is breached. 'nuff said.

The push behind 2FA isn't so much because high entropy passwords are vulnerable (except in a phishing context, but there TOTP is equally vulnerable) -- the momentum behind 2FA is because we can't convince people to stop using '123456' as a password.

Post reply on HN