14 ms·
The 773M Record “Collection #1” Data Breach
- mpeg 8y agoFunny, I downloaded about 700GB of password dumps last week trying to figure out how someone got one of my passwords (no big deal, they never managed to access anything) Maybe it was this one.
- zaroth 8y agoTroy won’t store the passwords associated with the username, which is a choice I can absolutely respect. But as he discusses in the post, that leaves users knowing that their email address was in the data dump, but with no way of knowing which site it came from, or what password was breached. So while this increases the number of records in HIBP, and perhaps makes the password popularity tracker a bit more comprehensive, it still leaves users exposed. I know which password of yours was breached, and that information is now effectively public, but you probably don’t know where to find it yourself, and I won’t tell you which one it was. So I guess just assume all your passwords are cracked and use a password manager. I don’t really hold it against Troy, because again, I respect his decision not to store plains directly associated with usernames. He did as much as he was willing to with the data, and it’s better than nothing, but not great all the same.
- deleted 8y ago[deleted]
- damontal 8y agoHe has a service that lets you enter a password to check if it’s been pwned though. I guess these are disassociated from user emails?
- sliken 8y agoStill seems insane to upload your password.
- NoPicklez 8y agoHe has the "Pwned Password" search to allow you to narrow it down and he has a really good article that he links to explaining why despite its inconvenience. If I was him I'd do the same. HIBP is a side project of his and I wouldn't be able to sleep at night knowing I have the responsibility of securing billions of email & password combinations. At the risk of the breach of those accounts adding fuel to the credential stuffing fire and reducing his overall credibility when providing security advice which is his primary occupation. Too risky.
- ehsankia 8y agoThere wouldn't be any inconvenience if your password manager did its job of helping you manage your passwords. 1Password has implemented a feature that helps you easily check all your passwords, I'm honestly surprised it's taking so long for the others to do too. The data is there, there's a super easy API, it doesn't take that much effort...
- rerx 8y agoEnpass has such a feature too. I just had it check all my passwords in the light of this new breach.
- deleted 8y ago[deleted]
- zawerf 8y agoI am not sure you should put too much confidence in the "pwned password" search. I know one of the weak password I stupidly reuse everywhere was compromised since I had someone buy something with my paypal account. But it comes up as clean in the password search. So it was probably cracked from one of the leaked hashes but the plain text was never entered into the public dumps.
- M2Ys4U 8y agoWell one can't prove a negative, that is that your password _hasn't_ been leaked. Knowing that - for sure - a password has appeared in a breach is very useful.
- AdmiralAsshat 8y agoThe slightly annoying thing here is that I already use a password manager, so while the impact to me is minimal, I wish I knew which password specifically I have to rotate, instead of assuming that I need to rotate, like, all of them...
- jarfil 8y agoWhat we may need is the next step: a standardized way of changing passwords that would allow us to rotate them in bulk directly from the password manager.
- Rychard 8y agoYou might be interested in this, from just over a month ago: https://news.ycombinator.com/item?id=18618193 https://news.ycombinator.com/item?id=18618193
- Groxx 8y ago(Not affiliated with, just a happy user of) 1Password does a pretty good job at this, you can find all HIBP-passwords in a single location: https://support.1password.com/watchtower/ https://support.1password.com/watchtower/
- shkkmo 8y agoWhy not use Pwned Passwords to check your passwords to see if any of them need to be rotated due to this breach or any other?
- sliken 8y agoSeems really weird to advocate people reveal their passwords to a random untrusted 3rd party. They do have an API that allows you to search for your password based on a truncated checksum, so you can find out if your password was leaked, without revealing the password.
- deleted 8y ago[deleted]
- tfigment 8y agoTroy's site does indicate which site breach it came from generally. I ran my emails and found it funny when myspace came up (and others I was aware of). I guess I did have an account there after all but I've used password safe for over a decade and always have unique passwords including that one from 2007.
- cm2187 8y agoBut most of these breaches are just aggregation of passwords he found like in this particular example. It doesn't tell you which website got hacked originally.
- rjf72 8y agoYou can search by password here: https://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords If you're as paranoid as you should be about then you can use an API to search using k-anonymity: https://api.pwnedpasswords.com/range/{hashPrefix} https://api.pwnedpasswords.com/range/{hashPrefix} There you can replace "{hashPrefix}" with the first 5 characters of the SHA-1 of your password. It will return a list of all SHA-1's that start with the given 5 character prefix, as well as how many times they've been 'busted'. Ideally it will not return the full SHA of the password you're testing, meaning you're in the clear. For testing purposes, the SHA-1 of "Passw0rd" is "21BD12DC183F740EE76F27B78EB39C8AD972A757". --------- Edit : I previously stated you could search directly by the SHA-1 of your pass alone (in the regular web interface). It looks like this feature has been removed since he's added the k-anonymity feature. So your options are searching directly by password, or using the k-anonymity hash prefix API.
- jancsika 8y agoWeird, I don't see any entries for password or password1 in there.
- umeshunni 8y agoI get this when I try 'password': Oh no — pwned! This password has been seen 3,645,804 times before
- rjf72 8y agoI assume he was sending in the SHA-1s. And yeah, it looks like he (Troy Hunt / site operator) disabled the direct search by SHA-1 now that he's enabled the k-anonymity API. Was able to edit and update my original post to reflect this.
- schmich 8y agoI wrote a Ruby script to check passwords back when the Pwned Passwords V2 API was introduced. I've added a second script to check a bulk list of passwords in a plain-text file. https://gist.github.com/schmich/aeaffac922271a11b70e9a79a5fee19c https://gist.github.com/schmich/aeaffac922271a11b70e9a79a5fe...
- x0x0 8y agoFor me, it was leaked through boltcd, elance, and reseller ratings. All those emails had been regularly leaked. I know because every time I register for a site I use site@mydomain.com as my email.
- jethro_tell 8y ago>So I guess just assume all your passwords are cracked and use a password manager. I mean I do, and that's why I have 100+ passwords that MIGHT be compromised. I don't even know where to start? Seems like the password should be shareable if you control the email or something like that. Fuck, I'd take a cc style last four type redaction or something.
- tokyodude 8y agoI know which passwords were breached by all the emails I get telling me "we know your password is XXXXXXXXX. Pay up or else". There's 4 or 5 in the first 30 messages in my email spam folder. >:(
- rbanffy 8y ago> So I guess just assume all your passwords are cracked and use a password manager. Even if it's not in the HIBP base, you should always assume that. That's why you should always enable MFA everywhere it's possible and consider all services where it's not already compromised.
- mpeg 8y agoYou can check the sites involved in the pastebin directory list though.
- Angostura 8y agoHmmm? He tells you which breach it came from, so in my case I know LinkedIn, Adobe, Dropbox, Binweevils (thanks kids!)
- hadrien01 8y agoIn my case I have an email that was found in Collection #1, but without knowing which site(s). It's an information I'd like to know.
- cm2187 8y agoI took the habit of giving a unique random alias to every website or service who requires my email. The additional benefit is that I can single out where the breach (or spam) came from if I see that unique alias. I only started doing that about 3-4 years ago and so far only the dailymotion breach popped up. You can also do that with gmail by using the login+alias@gmail.com syntax but it's well known and trivial for a hacker to defeat.
- giarc 8y agoI've found that a lot of sites will not accept an email with a + in it nowadays.
- priansh 8y agoThis is frankly terrifying and very ironic. Websites put so much effort into tracking every little thing about their users, from where they come from to what they do. Hotjar (https://hotjar.com https://hotjar.com) goes ahead and tracks mouse movements and now we even have crazy f-ed up startups like Peekmap (https://peekmap.com https://peekmap.com) that claim to predict eye gaze without the webcam. And yet they get pwned so easily. So much effort into violating user privacy, so little effort into enforcing user security.
- markovbot 8y agoand receive no meaningful legal consequences. These people should be on the hook for all damage done with this dump, but they won't be, so it doesn't really matter. It's not ironic, it's just business as usual. Collecting data on users should be extremely risky, even if they consent to it's collection.
- stochastic_monk 8y agoExactly. It’s a matter of incentives. Without laws with teeth (IE, both consequences and enforcement), this will never change.
- AYBABTME 8y agoI think it's time for an external, trustworthy entity to spawn that would vet and endorse companies that respect their users. Something like the "USDA Organic" label but for user privacies. Maybe it'd be an EFF-like entity that audits companies in exchange for a fee and endorse that "Company X, and the product/services it uses, are respecting user privacy". We could then derive a chain of trust between companies, maybe have a browser extension that tells when we're using a website that is endorsed by such entity?
- btrettel 8y agoStandards could help too. I recently started setting up a phpBB forum for a personal project. Because I wanted to respect people's privacy as much as possible, I removed certain fields like the birthday so that they can't be entered. I disabled private messages to avoid keeping unneeded nominally private data. To contact a specific user, I allowed only emails sent via a form to prevent leaking a user's email address. And I installed an extension to allow users to delete their accounts. I was pleasantly surprised with how easy disabling birthdays and other profile fields were, but somewhat disappointed that allowing users to delete their own accounts wasn't built in yet. Would be nice for forum softwares to have a standard set of features and default behaviors that respect privacy. I doubt many people change the configuration settings I did. (If you have any other ideas for forum admins to make their forum respect privacy better, I'm interested.) I don't see why a forum should have a birthday field in particular. If COPPA compliance is a concern, just ask if the user is 13 or older at registration.
- markovbot 8y agoAnyone got a link to the actual data?
- roboyoshi 8y agoIn case nobody else has anything better: check the discord server of the-eye.eu .. My guess is that there is somebody who has it.
- arthurfm 8y agoThere's a .torrent of Collection #1 available here: http://www.mediafire.com/file/mluhkk4dpqi8vfm/Collection_1.torrent/file http://www.mediafire.com/file/mluhkk4dpqi8vfm/Collection_1.t... I found the link via a comment on /r/pwned [1]. I think it originally came from RaidForums [2]. [1] https://www.reddit.com/r/pwned/comments/agsjie/troy_hunt_the_773_million_record_collection_1/eeb0xix https://www.reddit.com/r/pwned/comments/agsjie/troy_hunt_the... [2] https://raidforums.com/Thread-Collection-1-5-Zabagur-AntiPublic-Latest-120GB-1TB-TOTAL-Leaked-Download https://raidforums.com/Thread-Collection-1-5-Zabagur-AntiPub...
- shmageggy 8y agoWhat's the latest consensus on the best password manager these days. I see he is recommending 1Password, but I recently found Bitwarden which looks quite good.
- unethical_ban 8y agoI use keepass. There are mobile apps and it can load from a cloud account.
- leetbulb 8y agoKeePass + Syncthing + YubiKey = Awesome, and free!
- triangleman 8y agoDoes keepass support yubikey out of the box or is there a certain plugin you use? What do you do about mobile?
- leetbulb 8y agoKeePassXC supports YubiKey out of the box. I do not access anything important via phone. I usually have my laptop nearby anyway.
- dsl 8y agoLastPass
- amanzi 8y agoBitwarden (https://bitwarden.com/ https://bitwarden.com/) is great and scores well in feature comparisons -- there was one on here recently. It's open source and has recently been audited too. It's free for the basic service, and really cheap for additional features. Great mobile apps and a web vault. And you can self-host. No bad points really.
- 8y ago
- Fudgel 8y agoIf you're using keepass, there are some plugins to check against HIBP: https://keepass.info/plugins.html https://keepass.info/plugins.html I'm gonna download the passwords offline and try this plugin: https://github.com/mihaifm/HIBPOfflineCheck https://github.com/mihaifm/HIBPOfflineCheck (you can grab the offline passwords from here: https://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords )
- randomthought12 8y agoMy email/pw is in there but there is easy way to know from which website so I don't know which password I have to change. All my passwords are randomly generated so they are different for all websites.
- aequitas 8y agoGot a few 'hacker' emails on one of my throwaway addresses on this list the last few days. That account was leaked before in another list so this was not worrisome as I get those all the time for this address. What did strike me as odd this time is that they did not end op in my spam folder but in my inbox. I'm using Gmail which normally for me has a very good spam/phishing detection. Somehow these mails came through though? Maybe its just an instance and Google was late to catch up with the cat/mouse game on this attack. Or these phishers are getting more sophisticated?
- ahje 8y agoGmail, and other large providers, use filters that adapt based on user input. If you report the messages as spam then the filter will learn, and hopefully catch them the next time.
- hnuser1234 8y agoHere's one more record to add: my HN password is my username. Feel free to use this account for anonymous well-intentioned posting.
- hnuser1234 8y agoNice, thanks!
- hnuser1234 8y agoYou’re welcome, it may be an interesting social experiment to watch
- deleted 8y ago[deleted]
- hnuser1234 8y agoFWIW, this comment was not made by me, the creator of this account.
- dang 8y agoWe've banned this account. Please don't do signal/noise-destroying tricks on HN. If you want the account unbanned, feel free to email hn@ycombinator.com with evidence that you own it and a promise not to do stuff like this.
- gstn8zz 8y agoDownload torrents of collections 1, 2, etc. https://satoshibox.com/ggywi8ikt4e5kdrs24yu2soy https://satoshibox.com/ggywi8ikt4e5kdrs24yu2soy
- eitland 8y agoHeh, plausible deniability ... but with a non-trivial risk of someone else locking you out from your own account.
- stevekemp 8y agoI got a notification today that my domain has been included in this collection. But as far as I can see it is gibberish spam-mails. I see 500+ entries such as: fkdsjlfjldsf@example.com spamkdsjf31@example.com fsdjlfsdjkl@example.com i.e. None of these emails at my domain are real, nor have they ever been real. That said if you allow password-based authentication on a server which is shared you might consider using my PAM module: https://github.com/skx/pam_pwnd https://github.com/skx/pam_pwnd It does lookups of previously-leaked passwords. Best practice these days is SSH-keys for authentication, but this would cover weak sudo passwords too, etc.
- Darkstryder 8y agoReading this tweet ( https://twitter.com/troyhunt/status/1085095504197779456 https://twitter.com/troyhunt/status/1085095504197779456 ), I've just donated the price of a coffee to Troy ( https://haveibeenpwned.com/Donate https://haveibeenpwned.com/Donate ), and you should too. HIBP is quickly becoming a critical piece of the Internet security infrastructure, and Troy should be lauded for undertaking it basically by himself.
- spacemanmatt 8y agoI like the service. I just donated, too.
- hnuser12345 8y agoPlease donate big bucks to the guy who loves to show off his wealth on Twitter. Troy surely doesn't miss an opportunity to brag about having a portfolio of properties, a mansion on the gold coast, expensive cars, a jet ski, a boat, etc. I'm sure poor Troy needs your pocket money to pay for an estimated bill which is actually substantially less than what it actually will be. After that please also donate your hard earned money to Bill Gates. He voluntarily spends 100% of his time being a philanthropist. He also desperately needs some poor people to pay for his coffee.
- csbartus 8y agoso strange ... i’ve checked again if i was pwned and on the top there is a service i’ve never signed up - Apollo, a sales acceleration platform i’m a simple dev and never subscribed to a sales service ....
- ask2sk 8y agoI got the same. Anyone here know what is Apollo?
- LaurentS 8y agoSame here. I had never heard of them. Turns out they're a YC'15 startup (https://www.apollo.io/company/ https://www.apollo.io/company/). There are no passwords in the data they lost according to HIBP. They seem to collect personal data from various sources and help other companies increase sales.
- nabnob 8y agoSo not only do we have to worry about websites we actually use being compromised, but we also have to worry about these sketchy third-party companies that have purchased our data being hacked.
- twic 8y ago> Collection #1 is a set of email addresses and passwords totalling 2,692,818,238 rows. It's made up of many different individual data breaches from literally thousands of different sources. (And yes, fellow techies, that's a sizeable amount more than a 32-bit integer can hold.) I hate to be that guy [1], but no, that does fit in a 32-bit integer - as long as it's unsigned. From the tweet, it seems like SQL Server puts the result of a COUNT into a signed 32-bit integer, which really surprises me. [1] I lied, i love being that guy.
- mxscho 8y agoSomeone from a well-known leak forum is claiming that the "Collection #1" discovered by Troy Hunt is only part #1 of all available collections (there are at least 5, and additional other dumps). He also posted a screenshot of the original sales thread of the owner. The dumps together seem to have a total size of almost 1TB. Not sure whether it's cool to post any links here.
- weinzierl 8y agoThere is the rumor that it is called Collection #1 because it was part of a larger dump consisting of Collection #1, Collection #2, etc. There is also the rumor that the whole set was sold for - now hold on tight - the ginormous sum of $45.
- chkas 8y agoHIBP doesn't protect the privacy of searched passwords! Showing 20 bits of the password hash narrows down the possible passwords to one millionth. You should check it locally by downloading the password hash list.
- ksec 8y agoLet say my email appeared on Pwned list. And given most ( at least I think most ) people have zillions of web forums, services, sites, services using the email address. What should you do now? I mean editing and changing password in everyone of them seems like a daunting task. And many of those services I no longer use anyway. I am thinking of completely giving up the identity and start over, which seems easier. Or any other thoughts and comments? Edit: I will definitely pay Apple a monthly fee if there is some simple and easy way to have online identity using email along with FaceID or Touch ID as 2FA. Getting rid of password while increasing security is something that should have happened but has yet to happened.
- pps43 8y agoJust use a different e-mail and password for each web site.
- darekkay 8y agoOh, it must be Tuesday. I've just updated my blog post[0] with some password best practices and it's amazing how little has changed in the last 4 years. [0] https://darekkay.com/blog/another-password-leak-oh-must-tuesday/ https://darekkay.com/blog/another-password-leak-oh-must-tues...