Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


freitasm

BDFL - Memuneh
79156 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

#312403 13-Apr-2024 22:33
Send private message

Hi folks

 

Over the last few days, we noticed a couple of episodes where suspicious replies were posted on Geekzone. 

 

In one case, the account owner emailed me to say his account was compromised somewhere else and used on Geekzone to post spam from a US-based IP address. He only noticed it because he received a topic reply notification and he hadn't posted in that topic before. I was told the password was reused between different sites.

 

In another episode, a spam reply was reported and we noticed the post was from an Estonian-based IP address.

 

I suspect this could be either data leaked from the LastPass breach, or a data leak somewhere in New Zealand, and some Bad People (TM) are testing the passwords in smaller sites before going for the big ones (banks, stock, etc).

 

     

  1. Please ensure you use unique passwords for each site. 
  2. Use a password manager (not LastPass) to record all your unique passwords.
  3. Enable 2FA where possible, either using an Authenticator app or Yubikey if possible.
  4. SMS 2FA is not as safe, but if no other option is available, use it. 

 

We do not know your password on Geekzone and we have no way to read it. I have now implemented a login notification email to let you know when someone logged into your account.

 

 

 

PS. I suspect one recent data leak in New Zealand, but the disclosure did not mention passwords so I won't name it. 





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
cddt
1509 posts

Uber Geek


  #3217989 14-Apr-2024 08:44
Send private message

Thanks for implementing the login notification email. I can confirm it works! 





My referral links: BigPipeMercury




Wheelbarrow01
1711 posts

Uber Geek

Trusted
Chorus

  #3218461 14-Apr-2024 23:06
Send private message

I must have been living under a rock or something because I was completely unaware of this Lastpass data breach...

 

I've just exported my vault to a new Bitwarden account and I guess now I'll go change all my passwords after I delete Lastpass - I can't wait LOL

 

Thanks for the heads-up, otherwise I would have just carried on blissfully unaware....


Chills
160 posts

Master Geek

Subscriber

  #3218464 15-Apr-2024 00:11
Send private message

I thought LastPass was already gone along with Dashlane but I must just not be caught up. My personal recommendations are BitWarden and 1Password! 




Batman
Mad Scientist
29727 posts

Uber Geek

Trusted
Lifetime subscriber

  #3218478 15-Apr-2024 07:40
Send private message

freitasm:

 

     

  1.  
  2. Use a password manager (not LastPass) to record all your unique passwords.
  3. Enable 2FA where possible, either using an Authenticator app or Yubikey if possible.

 

 

 

 

wow i thought LastPass was the one and only, seems i'm mistaken

 

do you have to keep changing password managers like how we keep changing passwords?

 

any recommendation of the best password manager? not google?


Batman
Mad Scientist
29727 posts

Uber Geek

Trusted
Lifetime subscriber

  #3218479 15-Apr-2024 07:41
Send private message

Chills:

 

I thought LastPass was already gone along with Dashlane but I must just not be caught up. My personal recommendations are BitWarden and 1Password! 

 

 

i'm getting the feeling that one has to keep changing password manager like they are supposed to keep changing the password? oh dear


Behodar
10433 posts

Uber Geek

Trusted
Lifetime subscriber

  #3218480 15-Apr-2024 07:48
Send private message

I'm a moderator on another forum and we've seen similar things there, where "good" accounts suddenly have their email address changed and start posting spam from a different IP address. We agree with the suspicion that passwords were breached somewhere down the line.


freitasm

BDFL - Memuneh
79156 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3218492 15-Apr-2024 08:59
Send private message

Batman:

 

wow i thought LastPass was the one and only, seems i'm mistaken

 

do you have to keep changing password managers like how we keep changing passwords?

 

any recommendation of the best password manager? not google?

 



I may not understand what you wrote. Do you mean to imply you think other password managers were compromised? Because that is not what I wrote.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


 
 
 
 

Trade NZ and US shares and funds with Hatch (affiliate link).
Batman
Mad Scientist
29727 posts

Uber Geek

Trusted
Lifetime subscriber

  #3218493 15-Apr-2024 09:02
Send private message

freitasm:

I may not understand what you wrote. Do you mean to imply you think other password managers were compromised? Because that is not what I wrote.

 

i meant that not long ago people were recommending LastPass as the best password manager, and now I am hearing don't use LastPass.

 

what is the current best password manager? why are we no longer recommending LastPass?

 

thanks

 

(no i don't think password managers are compromised, i was just hoping you use one password manager and never need to change but it seems you have to change password managers from time to time for reasons I don't yet understand)


freitasm

BDFL - Memuneh
79156 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3218494 15-Apr-2024 09:04
Send private message

Bitwarden.




Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


Chills
160 posts

Master Geek

Subscriber

  #3218499 15-Apr-2024 09:34
Send private message

LastPass was just one of those companies that paid a lot for sponsorship spots on YouTube videos hence the big traction in their service.


ANglEAUT
2309 posts

Uber Geek

Trusted
Lifetime subscriber

  #3218500 15-Apr-2024 09:36
Send private message

Batman: ... one has to keep changing password manager like they are supposed to keep changing the password? ...

 

No, generally you do not need to change password managers regularly. Also, there are only a few on the market.

 

 

 

Batman: ... what is the current best password manager? why are we no longer recommending LastPass? 

 

chills above already suggested good options.

 

As to why LastPass is no longer recommended? Many, many, many reasons. Mostly the multiple breaches & then the insecure methods of implementation.





Please keep this GZ community vibrant by contributing in a constructive & respectful manner.


  #3218502 15-Apr-2024 09:50
Send private message

Login notification works here.... Notification shows my IPv6 address.





Gordy

 

My first ever AM radio network connection was with a 1MHz AM crystal(OA91) radio receiver.


  #3218505 15-Apr-2024 09:54
Send private message

How do I setup 2FA Yubikey on GZ?





Gordy

 

My first ever AM radio network connection was with a 1MHz AM crystal(OA91) radio receiver.


freitasm

BDFL - Memuneh
79156 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3218507 15-Apr-2024 10:05
Send private message

Gordy7:

 

How do I setup 2FA Yubikey on GZ?

 

 

You can't. We offer TOTP-based 2FA (Authenticator).





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


Batman
Mad Scientist
29727 posts

Uber Geek

Trusted
Lifetime subscriber

  #3218705 15-Apr-2024 15:32
Send private message

Thanks guys will check out bitwarden. I'm glad I didn't sign up for lastpass.

Just a question, is Microsoft authenticator ok to use? I have no issues using it, just wondering if it's safe

 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Amazfit Expands Active 2 Lineup with the New Active 2 Square
Posted 23-Jun-2025 14:49


Logitech G522 Gaming Headset Review
Posted 18-Jun-2025 17:00


Māori Artists Launch Design Collection with Cricut ahead of Matariki Day
Posted 15-Jun-2025 11:19


LG Launches Upgraded webOS Hub With Advanced AI
Posted 15-Jun-2025 11:13


One NZ Satellite IoT goes live for customers
Posted 15-Jun-2025 11:10


Bolt Launches in New Zealand
Posted 11-Jun-2025 00:00


Suunto Run Review
Posted 10-Jun-2025 10:44


Freeview Satellite TV Brings HD Viewing to More New Zealanders
Posted 5-Jun-2025 11:50


HP OmniBook Ultra Flip 14-inch Review
Posted 3-Jun-2025 14:40


Flip Phones Are Back as HMD Reimagines an Iconic Style
Posted 30-May-2025 17:06


Hundreds of School Students Receive Laptops Through Spark Partnership With Quadrent's Green Lease
Posted 30-May-2025 16:57


AI Report Reveals Trust Is Key to Unlocking Its Potential in Aotearoa
Posted 30-May-2025 16:55


Galaxy Tab S10 FE Series Brings Intelligent Experiences to the Forefront with Premium, Versatile Design
Posted 30-May-2025 16:14


New OPPO Watch X2 Launches in New Zealand
Posted 29-May-2025 16:08


Synology Premiers a New Lineup of Advanced Data Management Solutions
Posted 29-May-2025 16:04









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.