Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

This might be the mother of all password leaks, with billions of credentials exposed
BGR ^ | 7 Jun 2021 | Andy Meek

Posted on 06/09/2021 6:47:55 AM PDT by ken in texas

click here to read article


Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100101-110 next last
To: Billthedrill

Or . . . p@s$w0rD


61 posted on 06/09/2021 11:38:50 AM PDT by Sgt_Schultze (When your business model depends on slave labor, you're always going to need more slaves)
[ Post Reply | Private Reply | To 31 | View Replies]

To: ken in texas

Thanks for the info~


62 posted on 06/09/2021 11:39:30 AM PDT by Yardstick
[ Post Reply | Private Reply | To 56 | View Replies]

To: EasySt

Never had a computer with OS/2.................


63 posted on 06/09/2021 11:41:53 AM PDT by Red Badger (You can't wait until life isn't hard anymore before you decide to be happy............. Nightbirde)
[ Post Reply | Private Reply | To 55 | View Replies]

To: ken in texas; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ...
Hella password compromise ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to ken in texas for the ping!

64 posted on 06/09/2021 11:54:57 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: gitmo

“Or an Authenticator app that generates a passcode each time.”

Sounds like a good idea. Some of our vendors and accounts require that anyhow. But it would be even better if you could have that feature for every important site. I’ll try to find something like that. Thanks.


65 posted on 06/09/2021 11:59:31 AM PDT by MayflowerMadam (Faith, not fear. Faith, not faintheartedness.)
[ Post Reply | Private Reply | To 44 | View Replies]

To: discostu

“often involves user having to install apps on their phone”

What about using a PC? Do you think that would be applicable? We NEVER do anything financial on our phones, or even get email.


66 posted on 06/09/2021 12:00:58 PM PDT by MayflowerMadam (Faith, not fear. Faith, not faintheartedness.)
[ Post Reply | Private Reply | To 50 | View Replies]

To: ken in texas

is this only apple users?


67 posted on 06/09/2021 12:01:46 PM PDT by Chickensoup (Voter ID for 2020!! Leftists totalitarian fascists appear to be planning to eradicate conservatives)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Chickensoup; ken in texas
> is this only apple users?

It has NOTHING to do with Apple or Apple users. The gratuitous mention of Cook and Apple is bullsh*t pseudo-journalism to spice it up.

This leak is a huge list of ONLY passwords. No emails, no usernames.

68 posted on 06/09/2021 12:08:24 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 67 | View Replies]

To: MayflowerMadam

1 of the 2nd authentication apps I have to deal with also has a PC version. I don’t know about others.

Technically speaking it wouldn’t be anything financial on your phone. It’s just an app that you bring up when you’re logging in on your PC that sends a code (sometimes automatically, sometimes you have to enter the code on your PC) that basically says “yes, this login is legit”.


69 posted on 06/09/2021 12:14:44 PM PDT by discostu (Like a dog being shown a card trick )
[ Post Reply | Private Reply | To 66 | View Replies]

To: discostu

Tokenization is not new. We’ve been doing tokenization with Kerberos for decades. 2FA is really taking off with key providers out there everywhere, but the setup is very specific and requires maintenance to prevent outages and issues. With OAuth, OATH, and FIDO, there are many different standards, but they all work generally the same way. It’s still only a second factor. Passwords are still somewhat at play unless you’re going passwordless like so many large corporations.

My advice to prevent these breaches from impacting you: get a password management utility such as KeePass. Keep it local if you can. If it’s in the cloud, it can be stolen and brute forced. If you use KeePass, get a YubiKey, secure it with a certificate or OTP, and have a different, 20+ character passwords for EVERYTHING. Never reuse passwords. Ever. That’s why these breaches are so terrible.


70 posted on 06/09/2021 12:26:29 PM PDT by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 50 | View Replies]

To: dayglored

>>This leak is a huge list of ONLY passwords. No emails, no usernames.

you can search by email and find matches


71 posted on 06/09/2021 12:29:03 PM PDT by a fool in paradise (Lean on Joe Biden to follow Donald Trump's example and donate his annual salary to charity.)
[ Post Reply | Private Reply | To 68 | View Replies]

To: Dacula

I change passwords and I put a signature ID on subject lines. Anyone receiving an email purportedly from me that does not have that signature knows not to open it.


72 posted on 06/09/2021 12:29:47 PM PDT by arthurus ( covfefe rr)
[ Post Reply | Private Reply | To 8 | View Replies]

To: discostu

i heard that tiktok was snooping the clipboard

i also heard that President Biden has lifted the ban on using tiktok while calling for an investigation into spyware apps.


73 posted on 06/09/2021 12:32:40 PM PDT by a fool in paradise (Lean on Joe Biden to follow Donald Trump's example and donate his annual salary to charity.)
[ Post Reply | Private Reply | To 59 | View Replies]

To: dayglored
- The gratuitous mention of Cook and Apple is bullsh*t pseudo-journalism to spice it up. -

Agree. I considered deleting that part of the first paragraph but left it in lest I be jumped on for excerpting too little. ;-)

74 posted on 06/09/2021 12:39:09 PM PDT by ken in texas
[ Post Reply | Private Reply | To 68 | View Replies]

To: Red Badger

“In the 80’s, engineers - Dilbert types, all brought their OWN computers to work.”

In the 80’s ....

Long timeframe. By the mid-80’s all our engineers had company computers.


75 posted on 06/09/2021 12:42:35 PM PDT by TexasGator (Z1z)
[ Post Reply | Private Reply | To 16 | View Replies]

To: discostu

Gotcha. That’s what we do with Amazon and some investment sites. I’m hoping all of them begin to offer that feature. It would be a huge advantage whe it comes to security overall.


76 posted on 06/09/2021 12:46:39 PM PDT by MayflowerMadam (Faith, not fear. Faith, not faintheartedness.)
[ Post Reply | Private Reply | To 69 | View Replies]

To: discostu

“That’s the big benefit of the token system, it doesn’t matter if gets stolen. Since that token is only useful for your machine for about an hour “

I’m in over my head here but could we say that it’s good as long as your email address can’t be spoofed?


77 posted on 06/09/2021 12:48:34 PM PDT by cymbeline
[ Post Reply | Private Reply | To 59 | View Replies]

To: TexasGator

We had a poor company...................


78 posted on 06/09/2021 12:50:34 PM PDT by Red Badger (You can't wait until life isn't hard anymore before you decide to be happy............. Nightbirde)
[ Post Reply | Private Reply | To 75 | View Replies]

To: dayglored

so it is really not connected to anyone?


79 posted on 06/09/2021 12:54:13 PM PDT by Chickensoup (Voter ID for 2020!! Leftists totalitarian fascists appear to be planning to eradicate conservatives)
[ Post Reply | Private Reply | To 68 | View Replies]

To: rarestia

It’s definitely not new. But it’s spent most of its life as an open secret. Oauth has been around for ages, but nobody outside ‘nix world cared until a couple of years ago. Then MS started talking about it. Now it’s spreading like kudzu.


80 posted on 06/09/2021 12:56:29 PM PDT by discostu (Like a dog being shown a card trick )
[ Post Reply | Private Reply | To 70 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100101-110 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson