Amid Data Breach, Google, Mail.ru and Yahoo Claim 98% of Leaked Credentials Bogus (arstechnica.com)
Hundreds of millions of email login credentials -- affecting Gmail, Yahoo, Mail.ru (Russia's most popular email service), and Hotmail among other websites -- were being traded earlier this week in Russia's criminal underground. According to a report on Ars Technica, Google, Yahoo, Microsoft, and Mail.ru have now assured that the vast majority of leaked credentials are invalid. For instance, "More than 98% of the Google account credentials in this research turned out to be bogus," Google said. Dan Goodin reports: What has been clear all along to anyone paying attention is that the plaintext credentials recovered by Hold Security almost certainly didn't come from hacks on the e-mail providers. Instead, they most likely were collected by hackers who hit dozens, hundreds or thousands of third-party Web services over the years and dumped the account databases into a single list.
This is self serving and hard to disprove. So go for it!
"dozens, hundreds, or thousands" - that's quite a range. I hope we never describe a car accident that way
You are all Cows. cows say Mooo. Mooo! Mooo! Mooo Cows Mooo! Mooo say the cows. YOU POST PASSWORD AGE COWS!!!
... that was teh haxx0rz their fault too.
100% -/- 98% = 2%; 2% of 272,000,000 = 5,440,000 valid accounts & passwords. Getting a 2% success rate isn't so bad, is it?
When the copyright term is "forever minus a day", live every day like it's the last.
The rabble rallied in the cafeteria because a kitchen server spread a rumor the milk was only 2% milk and 98% water and adulterants. Now we get only skim.
Happiness in intelligent people is the rarest thing I know.
Ernest Hemingway
Of course only if you follow their definition of "bogus". That is "using names, addresses and other personal information that isn't quite in sync with that of the person registering the account".
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
*) People's email credentials are being sold in large numbers on the black market
*) If you choose to buy some of these, it's not unlikely that you'll get many outdated or bogus credentials
Or in other words, planet Earth is still spinning around that big hydrogen ball
Telling me that access to my gmail account was blocked 1 hour ago when someone tried to log into my account using the correct password in Dallas, TX (no where close to where I live).
I decided to change my password to be on the safe side, then not 10 minutes later I notice this story. Could be a coincidence, but maybe not.
Story1: Of the 100 million credentials leaked, 98% are bogus
Story2: 2 million valid credentials have been leaked
The second story still seems pretty serious to me...
"More than 98% of the Google account credentials in this research turned out to be bogus," Google said.
In unrelated news, security researchers discovered today that 'bogus' is the most common password in the universe. They theorize it may have something to do with accidentally allowing Keanu Reeves near a phone booth.
Real lawyers write in C++
3rd party login interfaces are evil
In putin's russia, acc vendors pwn you!
..because they couldn't be Ars-ed?
"..One hosts to look them up, one DNS to find them, and in the darkness BIND them."