Protip for the room: Use a password manager with a unique password for every service. Then when one leaks, it only affects that singular service, not large swaths of your digital life.
post
For me, if this happens, it has no impact since almost every page i sign up to has a unique password. The most important ones has mfa as well.
Use a password manager. Simple.
Right answer. In fact, the only viable answer.
Stuffing? Just in time for the holiday season!
Why did you censor yourself in the title?
The thing about this one is no one seems sure of the source (it appears to be from multiple sources, including infostealer malware and phishing attacks), so you don't know which passwords to change. To be safe you'd have to do all of them.
Some password managers (e.g. Bitwarden) offer an automatic check for whether your actual passwords have been seen in these hack databases, which is a bit more practical than changing hundreds of passwords just in case.
And of course don't reuse passwords. If you have access to an email masking service you can not only use a different password for every site, but also a different email address. Then hackers can't even easily connect that it's your account on different sites.
God fucking dammit, I fucking hate seeing people self-censor themselves on the internet.
Let's make a master list of all the emails leaked with their passwords, what could go wrong?
That’s not how it works
It's exactly how it worked. A company called synthient made a master list with all the leaked emails + all leaked passwords. Then they were hacked and it leaked
Synthient wasn’t hacked, as a security company, they aggregated tons of stealer logs dumped to social media, Telegram, etc.
They found 8% of the data collected was not in the HIBP database, confirmed with some of the legitimate owners that the data was real.
They then took that research and shared it with HIBP which is the correct thing to do.
I was also thrown off by the title they gave it when I first saw it, a security company being hacked would be a terrible look. but they explain it in the article. Should probably have named it “list aggregation” or something.
Someone should make a list of all the leaked credentials that got leaked.
Proud that my only pwned password is three decades old.
Yeah gotta make sure you never use the same password in multiple places, use a password manager.
Comprised of email addresses and passwords from previous data breaches,
So these are previously “hacked” data, and now the aggregator has been hacked?
top 50 comments