2,800 New Data Breaches with 80M Records Added
troyhunt.com
troyhunt.com
And still, just about every service that you have to make use of (your HOA, your insurance company, your government and so on) wants you to trust them with your data secured by a userid and a password that they will administer on infrastructure that they are most likely not competent to secure.
One of the best things to come out of the GDPR is the reporting requirements for breaches. You can expect a lot more of these updates in the future.
Edit: interesting, the link now goes to 'https://ghost.org/fail/', a 404, so go to https://www.troyhunt.com/
To a point. Imagine if some crafty hacker leaks Slack's entire message history across all companies. Think of the chaos.
Kind of weird to consider that maybe we haven't seen a catastrophic breach yet.
People died because of that one:
https://en.wikipedia.org/wiki/Ashley_Madison_data_breach#Imp...
[0] https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
[1] https://www.wired.com/2016/10/inside-cyberattack-shocked-us-...
[2] http://www.slate.com/articles/technology/future_tense/2015/0...
I wrote Troy a message, but I think it’s around midnight in Queensland and he might be offline.
https://webcache.googleusercontent.com/search?q=cache:jLWeTh...
I remember a few years ago creating an account on a small online clothes shop with a unique randomly generated email. I almost immediately started receiving unrelated spam on that email. Clearly their database had been breached. I still haven't received any notification on haveibeenpwned for that email. I am sure there is an enormous mass of breaches of small mom and pops sites that are out there, unknown to both the users and the owner of the sites.
I really do not like making accounts, especially where they are not required, such as when ordering something from some shop that I only intend to use once, or for my mobile phone company, who in their infinite wisdom have decided that having my email address is not enough to send me invoices, they need me to receive an alert that they have posted an invoice in their internal system for which they helpfully created an account that they mailed me the password for.
It really makes me wonder who comes up with these ideas.
Also, I just re-tested and it is still not working.
Your IP address: 1.2.3.4
Error reference number: 524
Cloudflare Location: Seattle
Another possible hint: opening the link in a FF private window works.
2,844 Separate Data Breaches (unverified): In February
2018, a massive collection of almost 3,000 alleged data
breaches was found online. Whilst some of the data had
previously been seen in Have I Been Pwned, 2,844 of the
files consisting of more than 80 million unique email
addresses had not previously been seen. Each file
contained both an email address and plain text password
and were consequently loaded as a single "unverified"
data breach.
Compromised data: Email addresses, Passwords
The problem is I have no idea what this breach is sourced from, so I don't know what account in particular was affected. Not Troy's fault, obviously, but it's basically just telling me, "Your e-mail address and a password to somewhere was found online somewhere." For all I know it's recycled data from a breach I already know about.At this point it's not really a big deal. I use a password manager and they're all random at this point, so I just need to figure out which one to rotate.
Hopefully at least it will push more people towards password managers and avoiding password reuse.
This of course is just one example, and not guaranteed to be an accurate one in this case.
I suppose the reason for omitting the filename is that Troy does not want to cast any unwarranted trust in the filenames, which is fair.
However, I think the real reason is privacy. If I recall correctly, there are certain breaches where HIBP redacts the website to protect privacy. A great example of this was ashleymadison. It kinda sucks when anyone that knows your email can learn you were on that site. It seems excessively hard to screen the entire list of 2800 items for such privacy concerns.
you can also search now for your addresses and see if you were affected.
And just because XYZ site was previously listed as a breach, doesn't mean it wasn't breached again with your new password
"Dark web" (lol) hackers are already going to be circulating the sources of this list and in any case could probably crack sha-1 reasonably quickly. So if you do a minimal amount of verifying the person who asks (e.g. ring their university) you can surely help the good guys with little risk of misuse?
> in any case could probably crack sha-1 reasonably quickly.
So that shouldn't bother you then.
And crackers will share unknown hashes to be cracked. So they can crowd source cracking far more effectively than the security community can.
That suggestion likely reflects reality.
*unless you have the original breach, then we are back at zero: its already compromised.
1Password then did a POC integration into their service so you can test if your password shows up in HIBP data.
https://blog.agilebits.com/2018/02/22/finding-pwned-password...
I get he doesn't want to do that and that is his prerogative. However, it does feel like we're so scared of things falling into the wrong hands that we hobble our ability to defend against hacks in the first place.
But no, there is likely no hope, lol
My host 'hacked' email address has been involved in 6 breaches.
Anyone beat that?
I also have a similar system now as you do, but really only for higher value accounts, not the niff naff forums stuff. And like you it's all randomly generated unique passwords so pretty safe.
None of my site specific emails have been breached yet, which is good as that would mean a major global provider had been breached.
That's why I do it.
Email Pwned sites
dropbox@... Dropbox
ffshrine@... Final Fantasy Shrine
github@... GeekedIn
linkedin@... LinkedIn
patreon@... Patreon
tumblr@... tumblr
(The Github one was using their OAuth - which kinda screws with the traceability)Probably someone just making up an address randomly but three times is a bit odd.
If some small site gets hacked there is a much smaller chance that it finds its way to Troy.
Sure: Zero ;)
But that's no real surprise, I try to keep the number of accounts I have to an absolute minimum which is one of the easier ways to avoid this fate.
2 years ago I started using 1password and "user+sitename@domain.com" so I'm no longer worried. I assume all accounts that I haven't migrated are compromised.
It'd be cool if there was some way of gently sharing with your friends and family whether or not they've been pwned -- maybe some kind of social network plugin or web app that generates emails for you to send to them. A key challenge would be being sensitive to their privacy, i.e., not coming off as creepy.
line 713
I guess this is also a good time to remind the general population that password managers are a thing and prevent such breaches from turning a "oh I don't visit that website anymore" into "oh sh*t my bank account just went to 0"
One small suggestion, though: I wouldn't harm to ask somebody to proofread public statements like this, especially since this is a highly trust-related topic. The density of typos is annoying to me even though I'm not a native speaker.
Hiring manager here, one who doesn't use HackerRank either. I'm in agreement with the premise, but I would likely decline an applicant unironically employing the tone of writing emphasized above given the implications against cooperation and teamwork.
"cute little" can be replaced with "case-specific" or "niche," maintaining the same general meaning while divorcing it from adversarial connotations.
https://inspiredelearning.com/resource/create-strong-passwor...