6 ms·
Err, no. Compromising your email account will for sure be the worst outcome. Everything else, including your OpenAI account, are accessible via that email acco
by werrett 3y ago
Err, no. Compromising your email account will for sure be the worst outcome.
Everything else, including your OpenAI account, are accessible via that email account + a password reset.
- crimsontech 3y agoBut the credentials are for stolen OpenAI logins, not stolen email logins. While there will be some people using the same password (I doubt many) the people selling them will no doubt have already validated and removed these from the set as they are obviously much more valuable.
- lolinder 3y agoI think they were just responding to OP's dismissal of leaked email credentials as a major threat vector: > Finding your email password might let me see some memos, but ...
- deleted 3y ago[deleted]
- SV_BubbleTime 3y ago> While there will be some people using the same password (I doubt many) Well, it’s clear you don’t work in IT.
- crimsontech 3y agoGiven that OpenAI is probably more poplar with people interested in technology I suspect most users would use a password manager and generate unique passwords. I work in security though so maybe I’m just surrounded by people that do. I’ve combed through thousands of credential dumps to perform password stuffing attacks and the success rate is always very low. I would be shocked if the sellers hadn’t already taken any credentials that work against the associated email account out before they listed the dumps for sale, given that email account access is way more valuable than access to someone’s OpenAI account.
- jmye 3y agoNo, you're right. I was thinking about the kinds of sensitive information that one might get access to via a single account - not about the use of that account as an attack vector for other accounts.