Over a billion passwords stolen

Valerion

Expert Member
Joined
Oct 13, 2003
Messages
1,967
Reaction score
36
Location
::1
A Russian crime ring has amassed the largest known collection of stolen Internet credentials, including 1.2 billion user name and password combinations and more than 500 million email addresses, security researchers say.

The records, discovered by Hold Security, a firm in Milwaukee, include confidential material gathered from 420,000 websites, including household names, and small Internet sites. Hold Security has a history of uncovering significant hacks, including the theft last year of tens of millions of records from Adobe Systems.

Full article: http://www.nytimes.com/2014/08/06/t...an-a-billion-stolen-internet-credentials.html
 
More here: http://mybroadband.co.za/news/security/107578-russian-hackers-steal-1-2-billion-passwords.html

Couple of things to take away from this breach:

The research company that discovered this breach, Hold Security, is going to offer a service to allow individuals to pay (possibly, not confirmed) to determine if you were compromised. The Hold webpage indicates that they even plan to ask for your passwords for this service.

http://www.holdsecurity.com/news/cybervor-breach/ said:
"We have developed a secure methodology for you to share with us a very strong (SHA512) cryptographic representation of your passwords for verification."

Security 101, don't share your password?

It's alarming that so many websites are still subject to SQL injection attacks. Is it really that difficult to establish and implement a solid coding framework, that is practical and promotes security? AFAIK, OWASP gives good guidance on web security.

Don't know what you guys do, but I change passwords on key profiles (banking, email, steam/origin/b.net, windows, router) every 30 odd days, following good password practices (length, complexity, non-replicated etc.). Takes an hour or so, but at least I know it's secure.

Over and above that, when I read articles like this, my first reaction is to change passwords on all my accounts, but how many people actually think of doing that? Just because you are tech savvy, does not mean that you are security savvy.
 
On another note, which password manager do you prefer, i.e. if you use one.
Keepass? Lastpass? Dashlane? 1Password? Built-in browser manager? Good ol' fashioned pen & paper?
 
On another note, which password manager do you prefer, i.e. if you use one.
Keepass? Lastpass? Dashlane? 1Password? Built-in browser manager? Good ol' fashioned pen & paper?

Brain
 
On another note, which password manager do you prefer, i.e. if you use one.
Keepass? Lastpass? Dashlane? 1Password? Built-in browser manager? Good ol' fashioned pen & paper?

I have them saved on my phone in a text file. However, only I can decode them, as the passwords displayed in plain-text on my phone are not the actual passwords, obviously. The decryption key is in my head. So if I do forget a password, I look at the file on my phone for that site.

Works for me, and even if someone steals my phone or gains access to that text file, they still will not be able to use my logins, most of which are 2-step verification anyway where possible.

B
 
On another note, which password manager do you prefer, i.e. if you use one.
Keepass? Lastpass? Dashlane? 1Password? Built-in browser manager? Good ol' fashioned pen & paper?

Keepass for me. Running it from a USB stick and it integrates nicely with Chrome so no need to type passwords. Also has the ability to store files etc.. in each link and you can synchronize the database [which is encrypted] to the cloud and acces it from there with Keepass for your mobile.

Saw there was an article a while back of flaws they found in Lastpass, think it has been fixed but was there apparently for an extended period of time.
 
I wrote my own encryption program for my iphone. Takes a pin as the decrypt/encryption key.
 
I have them saved on my phone in a text file. However, only I can decode them, as the passwords displayed in plain-text on my phone are not the actual passwords, obviously. The decryption key is in my head. So if I do forget a password, I look at the file on my phone for that site.

Works for me, and even if someone steals my phone or gains access to that text file, they still will not be able to use my logins, most of which are 2-step verification anyway where possible.

B

Interesting. What are you using to encode them? Something simple like each letter moving one to the left on the keyboard etc, or something more powerful - assuming your brain can handle that :p
 
Whoa I can't remember half my passwords, have to reset everytime I need to login

I prefer passphrases as they are easier to remember and more secure but I have a thing I do with standard passwords so that I can remember them on certain sites and still make them quite unique from each other.

Works about 99% of the time, once in a blue moon I forget a password for a site if I don't put it in regularly (more than once a year or so, like SARS with the funny way they insist your password must be put in.).
 
On another note, which password manager do you prefer, i.e. if you use one.
Keepass? Lastpass? Dashlane? 1Password? Built-in browser manager? Good ol' fashioned pen & paper?

My laptop has the fingerprint password reader so I just scan my fingerprint and it adds my password/username :).
 
Whoa I can't remember half my passwords, have to reset everytime I need to login

Funny enough, this is actually one of the preferred methods of password protection especially if you use a site rarely. The idea is that you set your password to something so complex you can't remember and don't re-use and just reset it every time.
Resetting it is effectively the same as getting a One Time Pin through your email then just as long as your email account isn't hacked because attackers can use this to get most of your passwords...
 
The research company that discovered this breach, Hold Security, is going to offer a service to allow individuals to pay (possibly, not confirmed) to determine if you were compromised. The Hold webpage indicates that they even plan to ask for your passwords for this service..

"Hold [Back] Security" ?

What keeps us from wondering if Hold Security is part of the operation? :p
 
Here are some of the latest guidelines I have picked up regarding password management:
1) Re-use an easy password for all non-sensitive data
It's impossible to remember all different passwords. Rather than re-using passwords on sensitive sites such as banking, etc, re-use passwords on all non-critical sites with something you can remember. This means you have less passwords to remember.

2) Be weary of password managers
Password managers are great, but it's easy for an attacker to find and if they can crack it, they get all your passwords.

3) Don't be afraid to write down a strong password
This is contrary to the age old belief, but it's better to use a strong, unique password and write it down than use a weak password. A hacker would need physical access to the paper and some context around where you might have used the password. This is better than using a weak password which millions of attackers are trying to break every day...

4) For password you use rarely, reset it on every use
For something you may only access rarely, it may be safer to set the password to something random that you'll never remember. When you need to access the site, use the password reset procedure which will email you a link to update your password. This is effectively the same as a one time pin.

5) Above all, ensure your email password is secure
As per 4 above, an attacker can usually reset most of your passwords with your email account. It doesn't help that many sites use your email address as the username.


One of the biggest risks with sharing passwords is that when one is compromised, you can't say for sure where it was compromised. It's difficult to hold a company to account if you use the credentials for many sites.

Some links:
http://www.pcworld.com/article/2455...mple-passwords-for-most-of-your-accounts.html
https://www.damballa.com/its-safer-to-write-your-password-down/
 
I've tried most methods:

AstroTurf's method of creating a master pass phrase; consisting of at least 12 characters, and then editing it based on the specific application/system/site's. Passwords easily became 16 characters long and it became a mission to manage and remember all my personal credentials (think of 10+ passwords that you have to remember and they change on a regular basis, regardless of whether I use the service, like SARS, frequently), never mind work related credentials.

Tried Bismuth and zippy's approach as well, although my solution was quite primitive and I didn't have extensive cryptography or dev skills. Think along the lines of a password protected Excel doc containing "encrypted" data (simple XOR encryption). That's before I realised how easy it was to brute force Excel or simply hacking Excel 2003, and reverse engineering XOR isn't too difficult. Haven't considered doing anything like this again, but it's always fun creating something practical and having layered security is always good.

I've tried KeePass, LastPass, RoboForm and Dashlane and was fairly comfortable using them. Each has their shortcomings in one way or another, but for the most part it's highly convenient. If you haven't tried password managers, I'd recommend going for KeePass, based on the overall value for money (it's free), usability, functionality and cross-platform support.
AFAIK, LastPass's servers were breached and users that had weak master key's were vulnerable. That's the problem if you choose a weak master key on any password manager. You can get two factor authentication to mitigate it though, like Google Authenticator or Yubikey (USD25).

I've been using SplashID for a few months now (requirement for work); works well for the specific purpose, but compared to other password managers, it's fairly limited. Rather install KeePass on a flash and use Google Authenticator for MFA...
 
The thing to realise about encryption is that there is no encryption method which cannot be broken. Its really about making the time and cost of getting your data not worth the effort.

I started looking at doing my own encryption when it came out that all these so-called industry products have in fact been compromised by the authors themselves building in backdoors. I then thought to myself that the obvious first point of risk is the author of the encryption software themselves. I don't know who they are.

If someone has a backdoor into their encryption, then its very cheap for the person who has that backdoor key to get to your relatively unimportant info. Because its so easy, since they don't have crack anything, they already have a key, then it becomes cost effective to steal your data.

If I wrote my own encryption, and it can be as simple as an ASCII shift algorithm using a multi-digit key code, then its actually harder for them to get my data and not worth the trouble, especially since its very cheap for them to hack 2 billion other people.
 
Top
Sign up to the MyBroadband newsletter
X