4 ms·
> My email appears in dumps on haveibeenpwnd too, because of database dumps. How is that evidence that there's a key logger on my system? If your password is i
by alxlaz 1y ago
> My email appears in dumps on haveibeenpwnd too, because of database dumps. How is that evidence that there's a key logger on my system?
If your password is in the dumps, too, like this person's passwords, then yeah, you might want to look into it.
- buckle8017 1y agoMany website still store plaintext passwords. Indeed the ones getting hacked are more likely to.
- alxlaz 1y agoFrom the linked article: > user names and passwords for logging in to various accounts belonging to Schutt have been published at least four times since 2023 in logs from stealer malware. So this isn't from website dumps with plaintext passwords.
- trollbridge 1y agoIf I did highly secure work (which I don’t), I’d set up a few honeypot machines and input my “secure credentials” (with a bogus password) into that repeatedly.
- alxlaz 1y agoYeah, inputing "secure credentials" traceable directly to you with what you'd hope is a bogus password is a very bad idea, especially if you're doing highly secure work.
- trollbridge 1y ago"Hope"? Generate random text, repeatedly type it in with AutoHotKey on honeypot machine, whatever rootkits are on there get garbled, useless data.
- alxlaz 1y agoThese aren't local credentials, these are credentials from various third-party websites that made their way into stealer logs. Garbled or not, using your personal email address for both legitimate purposes (e.g. Google Calendar, as the article points out) and honeypots isn't the best idea.
- lostmsu 1y agoThem not naming the sites is pretty telling.
- alxlaz 1y agoThey're linking to the original source of the news, which literally names "the sites".
- lostmsu 1y agoNo it does not. What sites appeared in the "stealer logs" with his email?
- alxlaz 1y agoAh, I thought you meant what sites list the stolen credentials. The exact overlap of websites across four separate stealer logs is enough to leak an email address pretty reliably. The only thing that's "telling" for is that they're not willing to dox this person.