Over 100k ChatGPT Account Credentials Made Available on the Dark Web
tomshardware.com
tomshardware.com
Wow, we really are at the point where you just need to insert "ChatGPT" into some boring random headline to make it news :)
No, we're at the point where the inserted item is ChatGPT, it's been many things in the past and I'm sure it'll be many other things in the future too. The pattern of cherry-picking to sensationalize headlines is as old as headlines.
Except companies with valuations in the billions should be monitoring the darkweb and automatically revoking/resetting compromised accounts. Every good-sized bank and credit card provider does it.
Almost all of my logins are generated 30-character passwords that are from/in my Bitwarden setup. I only have about 4 I have to remember (actual computer logins for work/personal and my password for Bitwarden). Exception being streaming sites (hulu, hbo max, etc) since getting 30 characters in on a TV is a pain.
I also have a host server passphrase that is words, since in the worst case, getting the random 30 was impossible in the 30s I had to enter it on a terminal view that can't paste, I had to completely reset it once (It was when first setting it up so nothing lost), but a pain.
The criminal furnished with keys
Desired fine secrets to seize,
But found nothing but trash:
Poems written slapdash!
Thus concludes a hilarious wheeze!But also not joking...every one of my chats really do end in limericks :)
so this is a collection of logins, passwords, etc. collected via some bit of malware on clients...not info gleaned from OpenAi server logs, which is what I got from the article initially
Most of us use unique passwords, a smaller portions uses unique emails per account, and in the future we will use public keys (passkeys).
Security is getting better I'm optimistic.
However we have to continue to push on providing as little information to these companies (i.e. they don't need my name, DOB, etc.). And in the future I look forward to where I store this information, and provide it just in time as needed for the specific use cases (i.e. it might be processed and checked by a 3rd party but it's never stored).
But the world population at large, it's very much not true. I don't think I know a single person outside the IT industry who uses a password manager for anything.
By now no one "should" be using the same password for multiple services, but it most likely still happens
Because as far as credential hacks go, 100.000 users is nothing, you can trivially get password lists thousands of times bigger than that on any given day of the week.
All the security is in the password. Using a password manager to automatically generate and store password almost fixes that. Then there are services that insist using 8 to 16 character passwords :shrug
They don't even have basics here.
MFA? Not even an option, even though they're using Auth0 and Auth0 can do that.
not sure if the billing info from chatgpt is entered on the same place
Depends on the use case I guess. I don't share private code with it for instance.
As of a month ago, sessions were still staying active even after a password change.
A little device/session management portal would be nice. Pretty standard these days.
You’re jumping to conclusions. OpenAI would be doing these users a favour by resetting their passwords, but their computers could still be infected.
> As of Monday, June 12 2023, new 2FA/MFA enrollments are temporarily paused.
https://help.openai.com/en/articles/7967234-does-openai-offe...
> "Logs containing compromised information harvested by info stealers are actively traded on dark web marketplaces," Group-IB said.
Though the 4th paragraph makes it more obvious.
I think pretty much every creator jumps the shark sooner or later. Like for the "screaming face previews" on YouTube, clickbait really does bait clicks.
OpenAI still "not available in your country".
I use it.
> The majority of the dumped credentials were found within logs connected to multiple information stealer malware families.
So, at least for the moment, OpenAI's security is not in question.
Which is not surprising at all, some of the phones owned by other people that I've had in my hands were so infested that barely anything worked. The amount of malware changing just about anything in the phone was comical.
> Jan Leike: I would love to understand better what’s driving all of this—what’s driving the virality. Like, honestly, we don’t understand. We don’t know.
> Part of the team’s puzzlement comes from the fact that most of the technology inside ChatGPT isn’t new. ChatGPT is a fine-tuned version of GPT-3.5, a family of large language models that OpenAI released months before the chatbot.
https://www.technologyreview.com/2023/03/03/1069311/inside-s...