DarkBeam leaks billions of email and password combinations
securityaffairs.com
DarkBeam leaks billions of email and password combinations
1–10 of 39 posts
Re: DarkBeam leaks billions of email and password combinations
#2Multifactor authentication or bust.
Re: DarkBeam leaks billions of email and password combinations
#3Oh the irony
Re: DarkBeam leaks billions of email and password combinations
#4The irony is darkbeam positions itself as a digital risk management platform. A based SOC2 security audit would reveal these vulnerabilities.
Re: DarkBeam leaks billions of email and password combinations
#5Culprit: non-password protected instances
Re: DarkBeam leaks billions of email and password combinations
#6The company I work for (stytch.com, we provide an authentication API) tracks breached passwords and, depending upon config, will invalidate passwords that have been leaked. Will be interesting to watch our logs over the coming weeks.
Re: DarkBeam leaks billions of email and password combinations
#7No evidence is presented that anybody but the security researcher noticed the unprotected data. The data is a compilation of previously leaked emails.
Re: DarkBeam leaks billions of email and password combinations
#8I suppose it would require a good few domains and or public mail boxes but imagine if one was to create n fake users for each real user. If any of the fake users log-in on their account all users are forced to change their password.
Re: DarkBeam leaks billions of email and password combinations
#9[deleted]
Re: DarkBeam leaks billions of email and password combinations
#10No evidence is presented that anybody but the security researcher noticed the unprotected data. The data is a compilation of previously leaked emails.
[deleted]