Slashdot Mirror


That 773M Password 'Megabreach' is Years Old (krebsonsecurity.com)

Security reporter Brian Krebs writes: My inbox and Twitter messages positively lit up today with people forwarding stories from Wired and other publications about a supposedly new trove of nearly 773 million unique email addresses and 21 million unique passwords that were posted to a hacking forum. A story in The Guardian breathlessly dubbed it "the largest collection ever of breached data found." But in an interview with the apparent seller, KrebsOnSecurity learned that it is not even close to the largest gathering of stolen data, and that it is at least two to three years old.

The dump, labeled "Collection #1" and approximately 87GB in size, was first detailed earlier today by Troy Hunt, who operates the HaveIBeenPwned breach notification service. Hunt said the data cache was likely "made up of many different individual data breaches from literally thousands of different sources." KrebsOnSecurity sought perspective on this discovery from Alex Holden, CTO of Hold Security, a company that specializes in trawling underground spaces for intelligence about malicious actors and their stolen data dumps. Holden said the data appears to have first been posted to underground forums in October 2018, and that it is just a subset of a much larger tranche of passwords being peddled by a shadowy seller online.

29 comments

  1. The other 752 million passwords are by Anonymous Coward · · Score: 0

    Password.

  2. could be.. by Anonymous Coward · · Score: 0

    why i haven't gotten any email since 2015?

    1. Re:could be.. by Anonymous Coward · · Score: 1

      No, you have to *really* kill Outlook. That message in the lower right corner that you are connected and all folders are up to date is a flagrant lie. Restart Outlook, and that message will complain about not being able to connect to the server and say "last updated" a minute or two before you restarted Outlook.
       
      Worst mail client ever.

    2. Re:could be.. by omnichad · · Score: 1

      You assume both that they're running Windows and that they've had 4 years of uptime? What kind of fantasy world do you live in?

    3. Re: could be.. by Anonymous Coward · · Score: 0

      Probably one where the admin is competent and not running Windows 10.

    4. Re:could be.. by Anonymous Coward · · Score: 0

      Lick my ovaries. You can get Outlook on every platform these days. I work for a tech company in SF. We get a new MBP every year and have every Office product under the sun, son.

  3. Remember kids! by Merk42 · · Score: 1

    Have a unique password for each and every site you visit, and then also change them often to the point where they aren't memorable and you end up using 'forgot password'. To get around that, use a password manager, and have everything linked to a single point of failure!

    1. Re: Remember kids! by Anonymous Coward · · Score: 0

      Gee, I was told we could have Nazi-like security and freedom. Maybe security is at the expense of freedom? Hmm...

      Yikes! I hope I didnt just commit a thought crime. Heil Hitlary as mandated by law!

    2. Re:Remember kids! by DidgetMaster · · Score: 1

      Remember to also have very strong passwords for all those sites that make you sign up just to download some trial software or to read an article! I am terrified that someone might guess my '1234' password to that site I visited 5 years ago (and will probably never visit again) and gave them a bogus email address (sorry bob@nowhere.com if you are getting lots of spam) because they could log on as me and steal....er, well nothing. Never mind.

  4. We should all know better any way by Anonymous Coward · · Score: 0

    Than to trust anything to be safe online. Hijacking Hotmail used to be as simple as guessing their single security question.

  5. 773M password breach? by CrimsonAvenger · · Score: 0

    Title says 773M password breach.

    TFS says 773M email addresses and 21M passwords.

    Is it even possible for our editors to make TFS and title consistent, never mind TFS and TFA?

    For that matter, why is the link for TFA to a /. post from yesterday, and not consistent with that /. post, much less itself?

    --

    "I do not agree with what you say, but I will defend to the death your right to say it"
    1. Re:773M password breach? by Anonymous Coward · · Score: 0

      TFS says 773M email addresses and 21M passwords.

      Perhaps there are 773M email addresses with password hashes and of those 21M has been cracked?

      Just guessing since I haven't read TFA, because Slashdot.

    2. Re:773M password breach? by jlockard · · Score: 2

      It says 773M email addresses and 21 million *unique* passwords.

      I think the key here is that associated with those 773 million email addresses, there are 21 million unique passwords. So, they have 773 million email address entries and there are passwords associated with those 773 million email addresses, and of those 773 million passwords, 21 million of them are unique.

      So, if I were setting up a password cracker, I could preload it with those 21 million unique passwords and I'd have a pretty good start.

      --
      --JLockard - "Some mornings, it's just not worth chewing through the leather straps." - Emo Phillips
    3. Re:773M password breach? by thegarbz · · Score: 1

      No TFS says 21M "unique" passwords. It's perfectly consistent when you realise a large portion of them are "12345678"

    4. Re:773M password breach? by Anonymous Coward · · Score: 0

      The parent needs to see your reply.

  6. Not only is it years old, it is useless by Mr.+Dollar+Ton · · Score: 1

    But you knew this already - you've surely received several "Hi, I'm a hacker, I installed a trojan on your router" spam crap, you've identified (by the password) the crappy website it was stolen from, maybe even changed it, then you checked the mail headers, saw that it came from a PC from India or Saudi Arabia and went on with your daily life.

    After all, you're a "hacker" on Slashdot.

  7. That 773M Password 'Megabreach' by grep+-v+'.*'+* · · Score: 1

    That 773M Password 'Megabreach' is Years Old

    OMG -- my password is "Years Old" -- they finally GOT me!

    Now they can change my free Pandora account to listen to whatever stations they want (albeit with commercials) and I can't stop them. Whatever shall I do?

    --
    If the universe is someone's simulation -- does that mean the stars are just stuck pixels?
  8. Don't change most passwords, do have a system by raymorris · · Score: 4, Insightful

    The current official guidelines, and what I've been saying for a long time, is don't change most passwords regularly. Exactly because you need to remember them.

    We can conveniently separate passwords into low-impact (Slashdot) and high-impact (banking and email). Frankly, my Slashdot password doesn't need to be super secure. It can even be the same as my Discus password.

    We want high-risk sites to have long passwords, and while we need to remember the password, there is some advantage to occasionally updating it. A way to achieve both is to *add* a couple characters every year or so. Maybe in 2005, a passphrase of "yummY pickle leaf$" was good enough. In 2006, I'd make it "yummY pickle leaf$ cake" or "yummY red pickle leaf$". I've changed it, but I'm leveraging my existing memory of it.

    For low-risk sites, one can have a shared base passphrase and add an extension. So:

    Slashdot: BarBoltCamSL
    Reddit: BarBoltCamRE
    Discus: BarBoltCamDi

    That's not super secure, but I don't need my Slashdot posts to be super secure.

    1. Re:Don't change most passwords, do have a system by Anonymous Coward · · Score: 0

      Changing a few characters is pointless because that's exactly what an attacker would do and hack your new password in about 30 seconds.

      Oh but you think you can move the characters around or other convoluted idea. No, that's not going to work, you have no idea how cryptography works. That's WAY, WAY, too low entropy. Nothing short of a completely new password is going to work because even that will probably have too low entropy otherwise you wouldn't be able to remember it.

    2. Re:Don't change most passwords, do have a system by Anonymous Coward · · Score: 0

      Only if a hacker wants to specifically target YOU. Otherwise they are buying a list of a million users and if 30% of those are still good, they are done. They don't go to the other 70% and start trying to brute force a bunch of permutations because that is hard, detectable, and often the user would be notified of the failed attempts.

      Low hanging fruit.

    3. Re:Don't change most passwords, do have a system by antdude · · Score: 1

      /me logs into Ray's accounts. ;)

      --
      Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
    4. Re:Don't change most passwords, do have a system by grumpy_old_grandpa · · Score: 1

      You don't want to remember your passwords, and you don't want short similar passwords. Instead, auto-generate different long random strings for each site, and use KeePass or similar to store them with one high security master password.

      As a bonus, use different email addresses which point back to the site, so you can easily change them when they get hacked. E.g. slashdot2019@baz.com or baz+slashdot19@gmail.com.

  9. Stupid by argStyopa · · Score: 1

    ....not only is it years old, but the "is my password hacked" check is astonishingly stupid?

    So...if I'm worried that my pw might have gotten into the wild, I should "check it" by entering it into a nonsecure form on some dodgy unattributed site? Really?

    Should I also send them my bank access info so they can make sure that wasn't hacked as well?

    --
    -Styopa
    1. Re:Stupid by ceoyoyo · · Score: 1

      https://haveibeenpwned.com/ asks for your e-mail address and then tells you if it's included in any known e-mail / password pair dumps. Entertainingly, it also tells you which dumps, and, if it's known, which organizations they came from.

      They could be harvesting e-mail addresses I suppose, but I pretty much assume that ship sailed a long time ago.

      Maybe you were entering your credentials into the wrong shady website?

    2. Re: Stupid by Anonymous Coward · · Score: 0

      No, they added /Passwords so you just type a password and it tells you how many times it shows up in breaches. But it doesn't say which breaches like the email lookup does.

  10. Smart by Anonymous Coward · · Score: 1

    If you read about it, your password isn't sent. It requests all matching hashes with the same prefix as your password(which your browser hashes), then the browser checks for any matches in the returned data set.

    k-Anonymity.

    The only risk I see is that you accidentally enter your password into a fake version of the website that doesn't do that. For that, there is an API you can use directly.

  11. KeePass is good. Many password managers aren't by raymorris · · Score: 1

    KeePass is a good choice. "Or similar" leads to many bad options unless you're very, very careful.

    I'd still keep my banking and email password only in my head. Email is important because it can be used to reset all of your other passwords.

    Length of passphrase is more important than including punctuation or even randomish-case. Certainly adding a digit on the end and a punctuation mark doesn't help much, because everybody does "Whatever1!".

  12. Our company was brutal to password managers by raymorris · · Score: 1

    Speaking of other password managers, a few months ago Corporate Security at the company I worked for chose an official password manager for employees to use. The problem is, we're a security company, full of people who look for security flaws for a living, I've been told that choosing one was rough because people kept pointing out known flaws in each option. It couldn't have been nearly as bad as after they announced the choice, though. We ripped into it. Employees all over the company not only demonstrated why the chosen password manager was totally unacceptable, but so was every option that Corp Sec had suggested for consideration. It was brutal. Almost everything had known flaws - not to mention probably unknown flaws.

    They finally ended up suggesting, but not requiring, 1Password. You do have vendor lock-in with 1Password, I think. With KeePass you don't, so that's one I've used personally.*

    * Mostly I use one based on gpg which I wrote. Writing one is a really bad idea for most people. Only people who do cryptography and security for a living should even think about writing one. It just so happens I've been doing it professionally for 20 years.