Live data from Hacker News

The 111M Record Pemiblanc Credential Stuffing List

troyhunt.com

51–60 of 73 posts

Re: The 111M Record Pemiblanc Credential Stuffing List

#52
post #3

These data breaches where the source isn't known can be frustrating. As someone who already uses unique passwords for everything, there's not much I can do (change 500+ passwords?). And I can understand Troy's argument[1] for not sharing the leaked password, so that doesn't leave many other options. I guess I'll just start going through my saved passwords and use them to delete all of the old accounts I rarely use, m…

My solution for this is to use a unique email address for each site/ service. That way if I see that hn@mydomain.com has appeared in a breach, I know both where the leak came from and which password to change. Also helps identify the source of any spam emails...

spamgourmet.com is this idea as a free (and awesome) service.

Re: The 111M Record Pemiblanc Credential Stuffing List

#53
post #30

Earlier quoted context omitted.

I'm not sure why you're being downvoted when you're exactly right. I have lost a lot of respect for Troy Hunt when he pretty much turned his blog and HIBP into a native advertisement for 1Password; without any disclosure that he is being paid by 1Password.

I'm looking at: https://haveibeenpwned.com/ I see a link below the search box, which when I click explains he has "partnered" with 1Password, why, and why he liked it prior to the partnership. It also links to this: https://www.troyhunt.com/have-i-been-pwned-is-now-partnering... which has a lot more detail. That's not what I call "without any disclosure". And makes me wonder what your idea of "disclosure" would be.

If you received one of the breach emails, there is a 1Password ad in the middle with no obvious disclosure that it's an ad / affiliate link.

https://i.imgur.com/g5btx15.png

Re: The 111M Record Pemiblanc Credential Stuffing List

#54

These data breaches where the source isn't known can be frustrating. As someone who already uses unique passwords for everything, there's not much I can do (change 500+ passwords?). And I can understand Troy's argument[1] for not sharing the leaked password, so that doesn't leave many other options. I guess I'll just start going through my saved passwords and use them to delete all of the old accounts I rarely use, m…

I really don't think HIBP should even be publishing or notifying people about these. It's almost always existing breaches just merged together in a different way. If I went and grabbed the raw torrents and combined them in various ways I could make hundreds of different "credential stuffing" lists. Would HIBP list and notify people about all of them?

Re: The 111M Record Pemiblanc Credential Stuffing List

#55
post #7

Earlier quoted context omitted.

Gmail and other MTAs support +something in the e-mail address user part too. If you forget your password, you do have to dig through your e-mail and figured out which one you used, but this method does let you track down when someone sells/shares your e-mail address or 3rd parties.

this method does let you track down when someone sells/shares your e-mail address or 3rd parties. Unless they strip out the +something part.

Based on my experience this unfortunately does occur, as does removal of dots in the local part.

Re: The 111M Record Pemiblanc Credential Stuffing List

#56
post #19
post #8

So in the past I've advocated password algorithms (sometimes called password formulas): https://penguindreams.org/blog/password-algorithms/ I felt like they could bridge the gap between a regular person who is weary of having to look up every password using a password manager (although a lot of them make it easier with browser plugins and phone apps, but it's still an extra step). However, in light of the recent Gent…

As someone technically literate but doesn't use a password manager: I sign up for a lot of services on one device (home laptop) and then need to use them on another device (work laptop, phone). How does a password manager work for this? I currently have about ~15 different passwords I use. I know which to use based on how long I've been using the service. Why is this strategy ineffective?? At most a hacker could get…

I happen to use the open source password manager from Keepass.info. It works on a local password file protected by strong crypto. Then, I use Dropbox to sync that file from device to device.

The problem with using the same password on multiple sites is this: if any one site gets pwnd, it gets a lot easier for the cybercreeps to pwn your account on other sites (says Obvious Man).

It doesn't take much technical skill to credential-stuff--to hammer a lot of sites with a list of credentials. So, keeping the list of sites you actually use a secret is not effective.

This whole deal sucks. But it's real.

Re: The 111M Record Pemiblanc Credential Stuffing List

#57
post #31
post #6

Earlier quoted context omitted.

Once the huge password Torrent is updated with Pemiblanc (9 GB, last updated March 1, 2018), you can download it and scan it for all your passwords locally. Then you can determine which are pwned. You'll have to SHA-256 them all, but that shouldn't be too hard.

Check out a lower bandwidth approach: https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...

Thanks for pointing that link out, I hadn't come across that API before.

Re: The 111M Record Pemiblanc Credential Stuffing List

#58
post #53

Earlier quoted context omitted.

I'm looking at: https://haveibeenpwned.com/ I see a link below the search box, which when I click explains he has "partnered" with 1Password, why, and why he liked it prior to the partnership. It also links to this: https://www.troyhunt.com/have-i-been-pwned-is-now-partnering... which has a lot more detail. That's not what I call "without any disclosure". And makes me wonder what your idea of "disclosure" would be.

If you received one of the breach emails, there is a 1Password ad in the middle with no obvious disclosure that it's an ad / affiliate link. https://i.imgur.com/g5btx15.png

Worth noting that the same emails also solicit donations, and there is no disclosure on the donations page:

> If you loved this free service and want to know what goes into making it possible, have a read of the donations page. Buy me a coffee or a beer or just some time with the kids at a movie.

https://haveibeenpwned.com/Donate

Re: The 111M Record Pemiblanc Credential Stuffing List

#59
post #30

Earlier quoted context omitted.

I'm not sure why you're being downvoted when you're exactly right. I have lost a lot of respect for Troy Hunt when he pretty much turned his blog and HIBP into a native advertisement for 1Password; without any disclosure that he is being paid by 1Password.

I'm looking at: https://haveibeenpwned.com/ I see a link below the search box, which when I click explains he has "partnered" with 1Password, why, and why he liked it prior to the partnership. It also links to this: https://www.troyhunt.com/have-i-been-pwned-is-now-partnering... which has a lot more detail. That's not what I call "without any disclosure". And makes me wonder what your idea of "disclosure" would be.

Personally, I don't like that it starts with the reasons to not take money ("I've had many offers to sponsor HIBP, to monetarily reward me for product placement and indeed to buy the service outright. I've rejected every single one of them because I didn't want my motives to be questioned"), then it is a _long_ time before he explicitly says he is taking money ("Clearly, this is a commercial relationship - 1Password pays to get their product in front of people via HIBP").
Post reply on HN