11 ms·
Billions of login credentials have been leaked online
- r33b33 1y ago2FA makes this a non-issue, no? You will get notificaton if someone failed to log in.
- Asraelite 1y agoNot even necessary. Salted hashes are enough, assuming you used a strong password.
- ericmcer 1y agoYeah assuming you have a billion encrypted passwords what are you even gonna do? You could try to brute force and maybe get a bunch of common/weak ones but as long as your password is like 8+ chars and fairly unique you probably wont be a target. Unless they were storing them all unencrypted lol.
- cwmma 1y agoit looks like a lot of these are from key loggers not from database breaches, so salted hashes, while nice, solve a different problem.
- Asraelite 1y agoI didn't see that, yikes. That's one hell of a breach then.
- junon 1y ago> Sixteen billion is roughly double the amount of people on Earth today, signaling that impacted consumers may have had credentials for more than one account leaked Interesting use as "may have" as that would imply, mathematically speaking, that there are people who were impacted at least twice...
- legacynl 1y agoThe subject of that sentence was consumers. Individual consumers 'may have' multiple credentials leaked
- krunck 1y agoThe list might also span a large time period and contain multiple versions of a user's credentials.
- SV_BubbleTime 1y agoAlso, dead people had passwords.
- AnotherGoodName 1y agoA common dark web strategy is just to re-bundle old password leaks to sell to white hats looking to investigate such leaks. Which is an amusing scam and one of the problems with trusting anything on the dark web.
- 9rx 1y agoTo be fair, we really have no idea how many people are on Earth today. Eight billion is our best estimate, but we also recognize that many of the sources used are undercounted to some degree. What's hard to determine to what degree that might be. A somewhat recent article in Popular Mechanics [https://www.popularmechanics.com/science/environment/a64222314/human-population-count/ https://www.popularmechanics.com/science/environment/a642223...] suggests that recent data may indicate that the estimates are way off... But who knows? Granted, any discrepancy is probably not on the order of reaching 16 billion. An additional billion uncounted would be incredibly surprising. But also, the accounts don't necessarily equate to people still on this earth and maybe don't equate to people at all. Robots have been known to create accounts too.
- yzydserd 1y agoA co-author of the study you refer to was recently on the UK BBC podcast More or Less, debunking much of the press coverage of his study, specifically the headline of vast global underestimation. Rather, the study found rural distribution estimates may be inaccurate, not total population. Link to the 9 minute episode https://www.bbc.co.uk/programmes/p0lgv5vf https://www.bbc.co.uk/programmes/p0lgv5vf
- DidYaWipe 1y agoThis is a good reminder that forcing people to use an E-mail address as a user ID is a stupid and dangerous policy. Voted down by amateurs who set their Web apps up this way. Killing the messenger won't secure your users' credentials.
- foxygen 1y agoAs if users wouldn't just use the same username everywhere. So now besides telling them to use different passwords for every website, you also need to tell them to use different usernames.
- Kranar 1y agoBut you can't use the same username everywhere, for example doing a Google search of my username shows accounts on other sites that are not related to me. Doing a search for your username suggests that it is also likely taken on numerous other sites, including a rock-band named FoxyGen that I'm fairly confident you are not a member of.
- foxygen 1y agoWell, yeah, the same way you can't use the same password because some websites have weird rules about password length and characters. Doesn't change the fact that you will be able to use the same username in MOST websites, given you don't have a super common username. The only solution to this problem is a password manager, which most people won't adopt anyway.
- DidYaWipe 1y agoSo what? At worst, it's no worse. But by default, it's already way better. Why? Because all of our E-mail addresses are on thousands of spammers' lists. So if you hammer that list with a dictionary of popular passwords, you're going to get a bunch of compromised accounts right there. But even worse: When you force non-tech-savvy people to use their E-mail address as their ID, many are going to think they need to use their E-mail password as well. So now if one poorly-run site suffers a data breach, all of its users' E-mail addresses AND passwords are out there. Identity theft ahoy. Not to mention the loss of people's accounts when they change E-mail addresses; When Apple started requiring that Apple IDs be E-mail addresses, it created a massive problem of people having purchases scattered across multiple accounts because they'd create a new one when their E-mail address changed. After the outcry, Apple huffily declared that it wasn't going to let people consolidate their accounts. But back to the point: Allowing people to create a proper user ID as free-form text doesn't preclude them from using their E-mail address if they insist on doing so. But they should be encouraged not to.
- deleted 1y ago[deleted]
- temp0826 1y agoWill this make its way to haveibeenpwned or other services?
- deleted 1y ago[deleted]
- airstrike 1y ago> According to a report published this week, Cybernews researchers have recently discovered 30 exposed datasets that each contain a vast amount of login information — amounting to a total of 16 billion compromised credentials. That includes user passwords for a range of popular platforms including Google, Facebook and Apple. Can someone more knowledgeable than me explain how my passwords could have been leaked from Google or Apple? Or is this just bad reporting? It is my understanding that neither Google nor Apple have my passwords stored, and any password service they have like the iCloud keychain would presumably be encrypted. What am I missing?
- amy214 1y ago>Can someone more knowledgeable than me explain how my passwords could have been leaked from Google or Apple? Or is this just bad reporting? A lot of this data, probably 95% + is from mass leaks from hacked sites. Hacked some non-google non-apple site, maybe 3 years ago, maybe 10. Your login to that site is your email (@gmail.com) so there you go. your email may be in there several times with different passwords, corresponding to several hacked sites. if on whatever site, dropbox (which had been hacked this way), your dropbox login is same as google login.. there you go, that's how they did it. some hacked sites have your password in plaintext, some with a weak hash algorithm which easily got reversed, either way, outcome is your password is known rest of the passwords are from something now becoming more popular which are "stealer logs" - basically malware that's taking screenshots, scanning for bitcoin wallets, keylogging credentials, steam info etc, and logging it all. the stealer type systems have caught me eye in the past few years, the 2020s, but I'm sure that community existed prior, and certainly this type of software goes at least as far back as the '90s.
- nemomarx 1y agoThe password to your Google or Apple account?
- dist-epoch 1y agoKeyloggers, people reusing passwords
- 1y ago
- DyslexicAtheist 1y agothe article mentioned passkeys as a solution but imho is only a path towards vendor lock-in. Like, "we solve your security issue provided you do business only with us". That is neither "antifragile" nor resilient. It's just hype.
- xxpor 1y agoHow?
- tiagod 1y agoI have my passkeys in 1password and they work fine. One key for each service, I don't see the difference to normal passwords in terms of lock-in
- mnahkies 1y agoI'm probably missing something, so would be great to get a ELI5 for this. How does storing passkeys in a password manager materially differ from the very long/strong passwords I'm already storing in my password manager? (and it's matching against the domain around autofill etc)
- max1cc 1y agoCan't be phished. With a normal password manager, user error could lead to copying credentials and pasting out to a phishing page which is irrelevant with passkeys Autofill is a good point but it doesn't help your parent who thinks the thing is broken so they have to do it manually, rather than realising it's a phish
- tatersolid 1y agoA passkey never exposes a secret to the website, so neither malicious scripts (e.g. via ad networks or analytics “partners”) nor malicious browser extensions can scrape the password. Plus passkeys are inherently phishing resistant, and don’t rely on the end user being wary when autofill don’t work. Autofill doesn’t work a lot, due to broken sites blocking paste as well as stupid sites that have you enter your creds to into multiple domains. (Yes, I’m looking at you, United Airlines…)
- krupan 1y agoCan we be done with passwords yet? I see far too many sites offering a passkey option
- Larrikin 1y agoIf you have a password manager, what is the point of passkeys? I was having this discussion earlier with a friend and we could not think of a compelling case. They seem less portable and harder to use on multiple devices or new devices. The only thing I could think of was protection against copied sites, but most users using password managers also block ads which should block most scam sites and password managers just need to have more messaging for if you try to fill in credentials on a site that is different from the site information saved with the password
- master-12 1y agoMalicious website that looks like your bank can't get you to tell it your passkey, but you can type in your password. (WebAuth checks the domain before signing)
- msgodel 1y agoSure, here's my public ssh key: public.swiley.net/id_rsa.pub I've been using this with everything important and was just waiting for everyone else to realize it was better. Oh no wait, you wanted some retarded Windows/Apple thing that needs biometrics, locks everything to your pay for service/hardware, and has a worse security model. Nevermind just use a password.
- krupan 1y agoI agree that passkeys are overly complicated, but they are in no way a worse security model than passwords. That is ludicrous. The password security model is an incredibly low bar to clear if you want better security. Also, passkeys work fine on systems other than Windows/Apple
- gnabgib 1y agoDubious origin, lots of other copies: (17 points) https://news.ycombinator.com/item?id=44316114 https://news.ycombinator.com/item?id=44316114 (30 points, 3 comments) https://news.ycombinator.com/item?id=44318192 https://news.ycombinator.com/item?id=44318192 (12 points, 4 comments) https://news.ycombinator.com/item?id=44320243 https://news.ycombinator.com/item?id=44320243 (26 points, 15 comments) https://news.ycombinator.com/item?id=44321381 https://news.ycombinator.com/item?id=44321381 (9 points, 2 comments) https://news.ycombinator.com/item?id=44322204 https://news.ycombinator.com/item?id=44322204 (11 points, 2 comments) https://news.ycombinator.com/item?id=44322288 https://news.ycombinator.com/item?id=44322288 (10 points, 3 comments) https://news.ycombinator.com/item?id=44322588 https://news.ycombinator.com/item?id=44322588 (10 points, 2 comments) https://news.ycombinator.com/item?id=44328038 https://news.ycombinator.com/item?id=44328038
- jmward01 1y agoOur digital identities have become more valuable than most physical property but I still don't see society taking it seriously. People like my grandmother constantly shedding information to any pop-up that comes her way. Our governments not prioritizing this threat as a true top priority and properly funding it and taking action on it. (911 for digital crime maybe?) People not seeing others and properly shaming them and turning them in for digital crime like we would do if we saw property crime, etc etc. The scale of something like this is absurd, even if it is a lot of re-packaged data. The amount of time people will be dealing with the fall-out from just this one incident can likely be measured in thousands of people years. Or, put another way, this is on par with the impact of mass murder in term of lives altered. As a society we really need to make changes in our laws and behavior to really internalize how massive a problem this is before we can even start to address it.
- deleted 1y ago[deleted]