Troy won’t store the passwords associated with the username, which is a choice I can absolutely respect. But as he discusses in the post, that leaves users knowing that their email address was in the data dump, but with no way of knowing which site it came from, or what password was breached. So while this increases the number of records in HIBP, and perhaps makes the password popularity tracker a bit more comprehens…
Hmmm? He tells you which breach it came from, so in my case I know LinkedIn, Adobe, Dropbox, Binweevils (thanks kids!)
The 773M Record “Collection #1” Data Breach
61–70 of 128 posts
Re: The 773M Record “Collection #1” Data Breach
#62What did strike me as odd this time is that they did not end op in my spam folder but in my inbox. I'm using Gmail which normally for me has a very good spam/phishing detection. Somehow these mails came through though? Maybe its just an instance and Google was late to catch up with the cat/mouse game on this attack. Or these phishers are getting more sophisticated?
Re: The 773M Record “Collection #1” Data Breach
#63Re: The 773M Record “Collection #1” Data Breach
#64What's the latest consensus on the best password manager these days. I see he is recommending 1Password, but I recently found Bitwarden which looks quite good.
Bitwarden ( https://bitwarden.com/ ) is great and scores well in feature comparisons -- there was one on here recently. It's open source and has recently been audited too. It's free for the basic service, and really cheap for additional features. Great mobile apps and a web vault. And you can self-host. No bad points really.
This of course could happen in a company like 1Password and there is at some point that I need to make the call and trust the person(s) coding the password manager. I feel that with 1Password there's at least the large size of the company which would mean more eyeballs and accountability. There is also the history of the company at 12~ years. This includes vetting and buy in from larger companies, which inspires a vote of confidence.
FWIW Bitwarden checks off nearly all the other boxes for me and I think the single dev has done a seriously bang up job.
Re: The 773M Record “Collection #1” Data Breach
#65What's the latest consensus on the best password manager these days. I see he is recommending 1Password, but I recently found Bitwarden which looks quite good.
- long history - to me it's the original password manager
- frequent updates and always keeping up with relevant OS features, like iOS AutoFill which allows 1Password to be set as the default iOS password store: https://support.1password.com/ios-autofill/
- flawless experience
Re: The 773M Record “Collection #1” Data Breach
#66Here's one more record to add: my HN password is my username. Feel free to use this account for anonymous well-intentioned posting.
Re: The 773M Record “Collection #1” Data Breach
#67But as far as I can see it is gibberish spam-mails. I see 500+ entries such as:
fkdsjlfjldsf@example.com
spamkdsjf31@example.com
fsdjlfsdjkl@example.com
i.e. None of these emails at my domain are real, nor have they ever been real.That said if you allow password-based authentication on a server which is shared you might consider using my PAM module:
https://github.com/skx/pam_pwnd
It does lookups of previously-leaked passwords. Best practice these days is SSH-keys for authentication, but this would cover weak sudo passwords too, etc.
Re: The 773M Record “Collection #1” Data Breach
#68Troy won’t store the passwords associated with the username, which is a choice I can absolutely respect. But as he discusses in the post, that leaves users knowing that their email address was in the data dump, but with no way of knowing which site it came from, or what password was breached. So while this increases the number of records in HIBP, and perhaps makes the password popularity tracker a bit more comprehens…
You can also do that with gmail by using the login+alias@gmail.com syntax but it's well known and trivial for a hacker to defeat.
Re: The 773M Record “Collection #1” Data Breach
#69Here's one more record to add: my HN password is my username. Feel free to use this account for anonymous well-intentioned posting.
... but with a non-trivial risk of someone else locking you out from your own account.
Re: The 773M Record “Collection #1” Data Breach
#70Troy won’t store the passwords associated with the username, which is a choice I can absolutely respect. But as he discusses in the post, that leaves users knowing that their email address was in the data dump, but with no way of knowing which site it came from, or what password was breached. So while this increases the number of records in HIBP, and perhaps makes the password popularity tracker a bit more comprehens…
Troy's site does indicate which site breach it came from generally. I ran my emails and found it funny when myspace came up (and others I was aware of). I guess I did have an account there after all but I've used password safe for over a decade and always have unique passwords including that one from 2007.