2 ms·
It isn't the actual Gmail passwords that are leaked. One of my accounts is there, but the password is one I have used on other sites, never on the actual Gmail
by onestone 12y ago
It isn't the actual Gmail passwords that are leaked. One of my accounts is there, but the password is one I have used on other sites, never on the actual Gmail account.
- ndr 12y agoCan you disclose which site?
- onestone 12y agoCan't be sure, it's a "garbage sites" password which I've used too many times on untrusted sites. Any one of those sites could have been hacked, or had been a phishing gateway itself. Of course what I did was bad practice. One should store passwords in a secure password manager, and use a different (preferably 30+ chars) password on each site.
- dredmorbius 12y agoMy present "garbage site" practice is to pop open a session to mailinator.com to a randomly generated box name. Mailinator will give an alternate address that's a hash of the first, so that the address itself cannot be used to check. See below. I'll create a set of long passwords (20-30 characters) with pwgen. Those are input as name, email, and password fields (different for each). If I need to verify an email, I can. I don't record the values, they're throwaway. If the site rejects 'mailinator.com', there are other domains provided as alternates. Example: inache8baezo0aowahph@mailinator.com is also m8r-ds4te4@mailinator.com inache8baezo0aowahph@mailinator.com inache8baezo0aowahph@mailtothis.com (or m8r-ds4te4 at the other domains) The 'm8r' address can't be used to check for mail. Note, obviously, that anyone with the actual mailbox hash can check it. For example: http://mailinator.com/inbox.jsp?to=facebook http://mailinator.com/inbox.jsp?to=facebook Oh, there's even an RSS mailbox subscription, neat: http://www.mailinator.com/feed?to= http://www.mailinator.com/feed?to=
- rasz_pl 12y agoit has my ancient password from ~2008 for http://login.aeriagames.com/user http://login.aeriagames.com/user That company went under 4-5 years ago, and I seem to remember few forum (phpbb afaik) software/database breaches at the time.