1.4B Clear Text Credentials Discovered in a Single Database
medium.com
medium.com
I did found this: https://twitter.com/clinton_ngn/status/736247662866006018 But no real explanation
About 7/10 frequently contacted people were in the database (...!). About half of those let me know that the passwords were not in use anymore. The other half was very, very grateful...!
It was a great time to remind them about password managers, 2fa, etc.
Silly marketing fluff from yet another "threat intelligence" snake oil outfit.
Anyone can compile a list such as this from other big dumps without much trouble, you just need some disk space.
Err, it actually increases its relevance and impact. With the same database now a hacker can reach multiple services...
> I have compiled it, I just want to show how big is password reuse problem for security community, and how easy was to crack those hashes using open source software.
proceeds to list domain names that are aliases of one another
Also the whole describing the thing as a database and saying it's fast because it's alphabetical...
At least describe what kind of database you're talking about so we can understand why an index isn't possible.
This database makes finding passwords faster and easier than ever before. As an example searching for “admin,” “administrator” and “root” returned 226,631 passwords of admin users in a few seconds.
Out of 1.4B credentials there are only 226K for admin, administrator and root?
I think that would explain why admin, administrator and root are rarely used as usernames.
Odd thing, I checked with other people, and they don't remember those as old passwords.
I even found passwords I don't remember...
https://www.reddit.com/r/netsec/comments/7ikbzo/14_billion_c...