SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    773 Million Password "Megabreach" is Years Old
Date    Saturday January 19 2019, @07:42PM
Author    takyon
Topic   
from the there's-lots-more-where-that-came-from dept.
https://soylentnews.org/article.pl?sid=19/01/19/1934241

martyb writes:

Security maven Brian Krebs, possibly best known for his blog Krebs On Security, recently posted an article that puts a damper on the kerfluffle about a huge e-mail and password breach that has been recently announced: 773M Password 'Megabreach' is Years Old:

My inbox and Twitter messages positively lit up today with people forwarding stories from Wired and other publications about a supposedly new trove of nearly 773 million unique email addresses and 21 million unique passwords that were posted to a hacking forum. A story in The Guardian breathlessly dubbed it "the largest collection ever of breached data found." But in an interview with the apparent seller, KrebsOnSecurity learned that it is not even close to the largest gathering of stolen data, and that it is at least two to three years old.

The dump, labeled "Collection #1" and approximately 87GB in size, was first detailed earlier today by Troy Hunt, who operates the HaveIBeenPwned breach notification service. Hunt said the data cache was likely "made up of many different individual data breaches from literally thousands of different sources."

[...] Collection #1 offered by this seller is indeed 87GB in size. He also advertises a Telegram username where he can be reached — "Sanixer." So, naturally, KrebsOnSecurity contacted Sanixer via Telegram to find out more about the origins of Collection #1, which he is presently selling for the bargain price of just $45.

Sanixer said Collection#1 consists of data pulled from a huge number of hacked sites, and was not exactly his "freshest" offering. Rather, he sort of steered me away from that archive, suggesting that — unlike most of his other wares — Collection #1 was at least 2-3 years old. His other password packages, which [...] total more than 4 terabytes in size, are less than a year old, Sanixer explained.

tl;dr: What you've seen recently mentioned in the press is old hat, and nothing to be too terribly concerned about. On the other hand, there are other collections -- over 5 times larger -- that are even newer. That is something to be concerned about.

What to do? The old advice still applies: Don't reuse passwords. Do use long passphrases or passwords. Do enable two-factor authentication. Do use a password manager. Avoid putting your e-mail out on the web in plain text for bots to find.


Original Submission

Links

  1. "martyb" - https://soylentnews.org/~martyb/
  2. "773M Password 'Megabreach' is Years Old" - https://krebsonsecurity.com/2019/01/773m-password-megabreach-is-years-old/
  3. "The Guardian" - https://www.theguardian.com/technology/2019/jan/17/breached-data-largest-collection-ever-seen-email-password-hacking
  4. "first detailed" - https://www.troyhunt.com/the-773-million-record-collection-1-data-reach/
  5. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=31245

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, 773 Million Password "Megabreach" is Years Old on 2024-04-24 18:56:55