Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

This might be the mother of all password leaks, with billions of credentials exposed
BGR ^ | 7 Jun 2021 | Andy Meek

Posted on 06/09/2021 6:47:55 AM PDT by ken in texas

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 101-110 next last
To: Army Air Corps

Mine long gone, I’m afraid...................


21 posted on 06/09/2021 7:35:10 AM PDT by Red Badger (Jesus said there is no marriage in Heaven. That's why they call it Heaven.....................)
[ Post Reply | Private Reply | To 20 | View Replies]

To: Gay State Conservative

No-one can figure that one out. It’s too easy.


22 posted on 06/09/2021 7:36:21 AM PDT by Disambiguator
[ Post Reply | Private Reply | To 15 | View Replies]

To: cymbeline
All of that inconveniences users, and won't solve the problem described in the article:

hacked their way into the social app website’s servers and got their hands on more than 32 million user passwords stored in plain text

Correct best-practice is not to store the password at all, but to store a "salted hash" of the password. That's why a correctly designed site will let you update your password, but can't tell you what your current password is -- they don't have it.

If you have to store a password -- you shouldn't, but if you did -- then it needs to be stored encrypted. Ditto for high-security data like SSNs, etc.

If there's a 99% cause of hacking, it's people running stuff they get as email attachments. For awhile, M$ Outlook even ran such stuff automatically! Talk about a security hole!

23 posted on 06/09/2021 7:41:22 AM PDT by Campion (What part of "shall not be infringed" don't they understand?)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Disambiguator

For years I had “qwerty” but I realized that that was too easy.


24 posted on 06/09/2021 7:45:49 AM PDT by Gay State Conservative (Trump: "They're After You. I'm Just In The Way")
[ Post Reply | Private Reply | To 22 | View Replies]

To: Red Badger

I better break out my BeOS cd.


25 posted on 06/09/2021 7:46:20 AM PDT by Organic Panic (Democrats. Memories as short as Joe Biden's eyes.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Gay State Conservative

I did not know your name was John Podesta!

😉


26 posted on 06/09/2021 7:50:28 AM PDT by ConjunctionJunction
[ Post Reply | Private Reply | To 15 | View Replies]

To: ken in texas

We had trouble getting into the Vanguard site this morning.


27 posted on 06/09/2021 7:52:56 AM PDT by MayflowerMadam (Faith, not fear. Faith, not faintheartedness.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: phoneman08

We have one computer strictly for all things financial — investments, banking, ordering, etc., and we don’t even access email on that computer. (We’d heard that many compromises and hacks are via email.) The PC where we web surf and get email never sees a credit card number or financial info.


28 posted on 06/09/2021 8:01:30 AM PDT by MayflowerMadam (Faith, not fear. Faith, not faintheartedness.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: wildcard_redneck

All of the scheduled reports run under my userID. When my Oracle password expires, I discover it because all the reports stop working. There is no warning. I finally found “select * from USER_USERS;” which gives the expiration date


29 posted on 06/09/2021 8:05:28 AM PDT by AppyPappy (How many fingers am I holding up, Winston? )
[ Post Reply | Private Reply | To 12 | View Replies]

To: ken in texas

I assure you - NO hacker in the world will EVER get my Facebook password!


30 posted on 06/09/2021 8:07:29 AM PDT by I cannot think of a name
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gay State Conservative

Great password but some places now require a non-alphabetic character or a number. I use p@ssword. It’s basically uncrackable.


31 posted on 06/09/2021 8:10:12 AM PDT by Billthedrill
[ Post Reply | Private Reply | To 15 | View Replies]

To: ken in texas

I am changing some today.

Unfortunately is is unclear which sites using those accounts are compromised (but I have my guesses based on which were and which were not).

ebay, facebook, et al should be required to make a public statement when their users’ data is compromised in a such a manner.

Same with the credit card companies and banks


32 posted on 06/09/2021 8:11:45 AM PDT by a fool in paradise (Lean on Joe Biden to follow Donald Trump's example and donate his annual salary to charity.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MayflowerMadam

I’ve been think of doing just that for some time now. I’m going to order a small Chromebook today.

One caveat, I won’t use it for online ordering. I’ve had a credit card hacked twice that way. No money lost of course, but a PIA nevertheless.


33 posted on 06/09/2021 8:23:55 AM PDT by phoneman08 (qwiyrqweopigradfdzcm,.dadfjl,dz )
[ Post Reply | Private Reply | To 28 | View Replies]

To: Campion

“If there’s a 99% cause of hacking, it’s people running stuff they get as email attachments.”

Maybe so. I’m not an expert. You’d think it would be possible at the administrative level to prohibit running any non-authorized program. I know that would be an inconvenience.


34 posted on 06/09/2021 8:29:26 AM PDT by cymbeline
[ Post Reply | Private Reply | To 23 | View Replies]

To: wildcard_redneck

“I would get no work done if I had to wait for a second person to sign in for everything I did.”

There’s a serious problem with bad guys gaining access to passwords so we need some sort of solution, or are we going to leave our giant systems vulnerable to hackers?

Obviously there’s not an easy solution that won’t be inconvenient or crippling to the way things are now done.


35 posted on 06/09/2021 8:33:03 AM PDT by cymbeline
[ Post Reply | Private Reply | To 12 | View Replies]

To: ken in texas

It looks like my email addresses and those of my wife are not in this compromise.


36 posted on 06/09/2021 8:37:30 AM PDT by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: a fool in paradise
- ebay, facebook, et al should be required to make a public statement when their users’ data is compromised in a such a manner. -

I completely agree with that. Instead, they prefer to keep it quiet.

37 posted on 06/09/2021 9:04:35 AM PDT by ken in texas
[ Post Reply | Private Reply | To 32 | View Replies]

To: phoneman08
- One caveat, I won’t use it for online ordering. I’ve had a credit card hacked twice that way. -

Ouch. One nice feature of my credit card is the ability to generate a virtual number that can be used one-time. I use that when ordering something online, particularly with a vendor I've never dealt with before.

38 posted on 06/09/2021 9:08:49 AM PDT by ken in texas
[ Post Reply | Private Reply | To 33 | View Replies]

To: cymbeline

2-factor authentication... you login... they text your cell phone a temporary key that’s good for like 10 minutes... you complete the login. Practically mandatory for online banking these days.


39 posted on 06/09/2021 9:16:20 AM PDT by Tallguy
[ Post Reply | Private Reply | To 7 | View Replies]

To: phoneman08
I’ve even considered buying a cheap Chromebook to use only for banking and investment log-ins.

You must be joking right? A GOOGLE Chromebook? Google, the most data hungry company in the world. That google? LOL

40 posted on 06/09/2021 9:31:48 AM PDT by Pollard
[ Post Reply | Private Reply | To 11 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 101-110 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson