5 ms·
DarkBeam leaks billions of email and password combinations
- promiseofbeans 3y agoOh the irony
- instagib 3y agoMultifactor authentication or bust.
- debarshri 3y agoThe irony is darkbeam positions itself as a digital risk management platform. A based SOC2 security audit would reveal these vulnerabilities.
- TedDoesntTalk 3y agoNo. Only if the database was exposed at the time of the audit.
- debarshri 3y agoWell, if you have some compliance automation. These things are caught very easily.
- hiddencost 3y agoThe things you're saying make it sound like you are harming clients by misrepresenting security to them. Security has to start from "when", not "if", precisely because it is fundamentally impossible to guarantee.
- 3abiton 3y agoCulprit: non-password protected instances
- cco 3y agoThe company I work for (stytch.com, we provide an authentication API) tracks breached passwords and, depending upon config, will invalidate passwords that have been leaked. Will be interesting to watch our logs over the coming weeks.
- choppaface 3y ago.. do you happen to have a service that lets users know if their password was in the breach?
- ShowalkKama 3y agohttps://haveibeenpwned.com https://haveibeenpwned.com
- cco 3y ago^yup, haveibeenpwned is the best public service to check this sort of thing. I don't think they've pulled it in yet.
- choppaface 3y agoyeah but do they have this breach yet? edit: the OP suggests there are some password lists that are known leaked but not in public leak docs. not sure if pwned is only public leaks?
- fbdab103 3y agoThis reminds me of [0] where they maintain composite lists of frequently used passwords. Also in the repo is probably my favorite pull request ever [1]. [0] https://github.com/danielmiessler/SecLists https://github.com/danielmiessler/SecLists [1] https://github.com/danielmiessler/SecLists/pull/155 https://github.com/danielmiessler/SecLists/pull/155
- downWidOutaFite 3y agoNo evidence is presented that anybody but the security researcher noticed the unprotected data. The data is a compilation of previously leaked emails.
- deleted 3y ago[deleted]
- Groxx 3y agoTo +1 this: >... from previously reported and non-reported data breaches.
- readthenotes1 3y ago"exposing records with user emails and passwords from previously reported and non-reported data breaches." I think you mean to say that there is no evidence presented precluding someone grabbing the data?
- downWidOutaFite 3y agoNot sure what your point is about non-reported, but that's still previously leaked data. It probably means stuff found in the dark webs.
- 6510 3y agoI suppose it would require a good few domains and or public mail boxes but imagine if one was to create n fake users for each real user. If any of the fake users log-in on their account all users are forced to change their password.
- Thorrez 3y agoCanary accounts: https://joesecurity.blogspot.com/2009/05/what-is-canary-account.html https://joesecurity.blogspot.com/2009/05/what-is-canary-acco...
- 6510 3y agoThanks, fascinating stuff. Now if you excuse me, I have swarms of canaries to make. https://canarytokens.org/generate https://canarytokens.org/generate
- deleted 3y ago[deleted]
- lelanthran 3y agoEach time a breach like this happens I want to download the file and check if 1. My emails are in the dataset, and 2. Any of my passwords are in that dataset. I really just want the collection of passwords so that I can use it as a check against any of my current passwords. [EDIT: I know about haveibeenpwned.com; I'm not asking for a service that I send a http request to to determine if a single username exists in the db, I want the db itself so I can chuck it into sqlite and check multiple records at a single time, quickly, for both usernames alone and passwords alone I also believe it's a bad idea to ask a third-party to perform the check. Even if you trust that third-party now, there is no way to ensure that trust in the future - i.e. it gets bought, breached or pwned itself in the future and best case scenario is that the record of your username lookup is available as "confirmed". Without visiting that site, no one would never know if that record was a throwaway or not.]
- hnlmorg 3y agoServices already exist that does this. Some password managers will check but the popular service often talked about on here is https://haveibeenpwned.com/ https://haveibeenpwned.com/
- lelanthran 3y agoThank you, I've edited my comment to be more specified
- GoblinSlayer 3y agoThey used to publish a torrent with hashes, but then went full SaaS.
- hnlmorg 3y agoDownload Have I Been Pwnds dataset then: https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader
- imposterr 3y ago
- choeger 3y agoThat sounds like a slam-dunk GDPR violation case and a hefty fine.
- stefanoco 3y agoThe data breach announcement is a bit vague on the meaning of “login pairs”. The best practices of breaches databases of the like of https://haveibeenpwned.com/ https://haveibeenpwned.com/ is to maintain records of login matter (username, email, password etc) in a strongly hashed format. This still enables searching and comparing but not extracting for later use. Why the database here looks like plain text is totally unclear. Or maybe the passwords are hashed here also (which anyway exposes email addresses)?
- fahrradflucht 3y agoDarkbeam was acquired by apexanalytix only two days ago. [0] Hope they are still happy with their purchase... [0] https://www.darkbeam.com/blog/apexanalytix-acquires-darkbeam https://www.darkbeam.com/blog/apexanalytix-acquires-darkbeam
- GoblinSlayer 3y ago>Use our personal data leak checker to see if your data – email, phone number, or password – has been leaked. What is the chance that my email and phone number aren't everywhere? Email and phone aliases are still rare.