3 ms·
Is there some kind of "statute of limitations" thing that means we're suddenly finding out about a string of breaches from 2012 now? Or is there some group tha
by throwawayReply 10y ago
Is there some kind of "statute of limitations" thing that means we're suddenly finding out about a string of breaches from 2012 now?
Or is there some group that is trading breach data privately that have themselves been compromised so that data coming from them is finally leaking out?
I'm now more worried about the 4 year delay in these things coming to light than the effect of the breaches themselves given how many times I now show up on haveibeenpwned.
- hap1o 10y agoI am curious to know what happened in 2012 that all these breaches occurred. I assume they are holding the data, and trying to squeeze what they can out of it all the way through. However this year there seems to have been a lot of massive breaches that year. does it all stem from one hack? 200m Yahoo accounts could lead to at least a few million LinkedIn accounts I would assume, maybe not as many as was actually compromised in the LinkedIn breach, but still. I just want to know if the same exploits were used in all of these instances. Or maybe they have just found backups for all these companies this year from 2012 and are using those. I don't even how that would happen.
- throwawayReply 10y agoIf they found a yahoo employee credentials in the linkedin hack (or vice-versa) then they don't need a million accounts, just those credentials. "Hackers who used an employee’s password, re-used from the LinkedIn breach, to access Dropbox’s corporate network and steal the user credentials" - from a unnamed source quoted in a techcrunch article. So maybe they also managed to traverse from linkedin to Yahoo or Yahoo to linkedin through similar password re-use.