The 111M Record Pemiblanc Credential Stuffing List
1–10 of 73 posts
Re: The 111M Record Pemiblanc Credential Stuffing List
#2I guess I'll just start going through my saved passwords and use them to delete all of the old accounts I rarely use, maybe with a little help from the GDPR.
[1] https://www.troyhunt.com/here-are-all-the-reasons-i-dont-mak...
Re: The 111M Record Pemiblanc Credential Stuffing List
#3These data breaches where the source isn't known can be frustrating. As someone who already uses unique passwords for everything, there's not much I can do (change 500+ passwords?). And I can understand Troy's argument[1] for not sharing the leaked password, so that doesn't leave many other options. I guess I'll just start going through my saved passwords and use them to delete all of the old accounts I rarely use, m…
Re: The 111M Record Pemiblanc Credential Stuffing List
#4These data breaches where the source isn't known can be frustrating. As someone who already uses unique passwords for everything, there's not much I can do (change 500+ passwords?). And I can understand Troy's argument[1] for not sharing the leaked password, so that doesn't leave many other options. I guess I'll just start going through my saved passwords and use them to delete all of the old accounts I rarely use, m…
My solution for this is to use a unique email address for each site/ service. That way if I see that hn@mydomain.com has appeared in a breach, I know both where the leak came from and which password to change. Also helps identify the source of any spam emails...
Re: The 111M Record Pemiblanc Credential Stuffing List
#5These data breaches where the source isn't known can be frustrating. As someone who already uses unique passwords for everything, there's not much I can do (change 500+ passwords?). And I can understand Troy's argument[1] for not sharing the leaked password, so that doesn't leave many other options. I guess I'll just start going through my saved passwords and use them to delete all of the old accounts I rarely use, m…
My solution for this is to use a unique email address for each site/ service. That way if I see that hn@mydomain.com has appeared in a breach, I know both where the leak came from and which password to change. Also helps identify the source of any spam emails...
Re: The 111M Record Pemiblanc Credential Stuffing List
#6These data breaches where the source isn't known can be frustrating. As someone who already uses unique passwords for everything, there's not much I can do (change 500+ passwords?). And I can understand Troy's argument[1] for not sharing the leaked password, so that doesn't leave many other options. I guess I'll just start going through my saved passwords and use them to delete all of the old accounts I rarely use, m…
Re: The 111M Record Pemiblanc Credential Stuffing List
#7Earlier quoted context omitted.
My solution for this is to use a unique email address for each site/ service. That way if I see that hn@mydomain.com has appeared in a breach, I know both where the leak came from and which password to change. Also helps identify the source of any spam emails...
You can also do this with Gmail by adding a . Or two randomly in your email.
Re: The 111M Record Pemiblanc Credential Stuffing List
#8https://penguindreams.org/blog/password-algorithms/
I felt like they could bridge the gap between a regular person who is weary of having to look up every password using a password manager (although a lot of them make it easier with browser plugins and phone apps, but it's still an extra step).
However, in light of the recent Gentoo vandalism, it seems like a user had their password formula figured out. Algorithms do guard against credential stuffing; that particular person was most likely specifically attacked. If you have a strong formula, it should take at least 7 or 8 passwords to begin to figure it out.
At a minimum, if you have non-tech friends who use a single password for everything, start them off easy: You should use a manager. It's the only way to guard everything. But if they don't want to go that route, at a bare minimum, recommend that they need three passwords. One that's highly secure for banks, employment and government. One insecure for everything else. And finally one for your e-mail which should be shared with nothing!
Password algorithms are a step up. It's a trade off of course: you are protected against credential stuffing and you don't need a manager; you can have a different password for every site without having to memorize a hundred password; only the exceptions to stupid password rules. The trade off: your algorithm probably sucks and if you're targeted specifically, someone can get to everything.
Every aspect of security involves trade offs. The various password management choices, along with their advantages and disadvantages, should be taught in high school.
Re: The 111M Record Pemiblanc Credential Stuffing List
#9These data breaches where the source isn't known can be frustrating. As someone who already uses unique passwords for everything, there's not much I can do (change 500+ passwords?). And I can understand Troy's argument[1] for not sharing the leaked password, so that doesn't leave many other options. I guess I'll just start going through my saved passwords and use them to delete all of the old accounts I rarely use, m…
Once the huge password Torrent is updated with Pemiblanc (9 GB, last updated March 1, 2018), you can download it and scan it for all your passwords locally. Then you can determine which are pwned. You'll have to SHA-256 them all, but that shouldn't be too hard.
The "huge pw torrent" is something I can just search on torrent trackers? Once I have the list, its just a list of passwords, or includes the emails? Then they're sha-256 hashed and I need to ..unhash them?
Re: The 111M Record Pemiblanc Credential Stuffing List
#10Earlier quoted context omitted.
You can also do this with Gmail by adding a . Or two randomly in your email.
Gmail and other MTAs support +something in the e-mail address user part too. If you forget your password, you do have to dig through your e-mail and figured out which one you used, but this method does let you track down when someone sells/shares your e-mail address or 3rd parties.