Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


freitasm

BDFL - Memuneh
79257 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

#222826 30-Aug-2017 11:52
Send private message

This huge (711 million records) leak would explain some email being sent from people's addresses and it contains email, password and SMTP server. 

 

I commented on there - Troy's Have I been pwned service is great but it's getting harder now to manage passwords. If you have a website leak and know the source you know where to change the password but with leaks that are username + password then it's harder to know where to change. And since he (rightly) do not disclose the passwords in the dumps then those already using unique passwords have a harder time. 

 

It seems we have to start using unique email + unique passwords to be able to better manage security. Those email aliases or emails with "+" in the address come handy here.

 

I recommend subscribing to the notification service at Have I been pwned so you receive notifications of leaks.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


Create new topic
kyhwana2
2566 posts

Uber Geek


  #1855236 30-Aug-2017 12:43
Send private message

Yet another reason to ensure you're using 2FA everywhere that supports it!

 




freitasm

BDFL - Memuneh
79257 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1855238 30-Aug-2017 12:48
Send private message

I have a long list of 2FA credentials but not many services support this yet.




Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


Rikkitic
Awrrr
18657 posts

Uber Geek

Lifetime subscriber

  #1855243 30-Aug-2017 12:56
Send private message

I don't have a cell phone. I don't need one and I don't want to have one. Is 2FA even possible without one? How would that work?

 

 

 

 





Plesse igmore amd axxept applogies in adbance fir anu typos

 


 




kyhwana2
2566 posts

Uber Geek


  #1855246 30-Aug-2017 13:04
Send private message

There are software and hardware tokens (Such as Yubikeys which do U2F). For TOTP software you can use something like Gauth https://chrome.google.com/webstore/detail/gauth-authenticator/ilgcnhelpchnceeipipijaljkblbcobl and enter the Secret manually..

 


Rikkitic
Awrrr
18657 posts

Uber Geek

Lifetime subscriber

  #1855275 30-Aug-2017 13:42
Send private message

OK, thanks. Would that also work for Geekzone?

 

 





Plesse igmore amd axxept applogies in adbance fir anu typos

 


 


kyhwana2
2566 posts

Uber Geek


  #1855285 30-Aug-2017 14:05
Send private message

Yep, geekzone uses the "TOTP" standard.

 

As with all things, make sure you keep a backup! (Of your password manager database and 2fa tokens. You can write down the TOTP "secret" on paper and store it in a safe etc)

 


dryburn
430 posts

Ultimate Geek


  #1855287 30-Aug-2017 14:10
Send private message

Does Troy's Have I been pwned service have a list of breached data content and then run that against the email you enter?


 
 
 

Cloud spending continues to surge globally, but most organisations haven’t made the changes necessary to maximise the value and cost-efficiency benefits of their cloud investments. Download the whitepaper From Overspend to Advantage now.
Oblivian
7296 posts

Uber Geek

ID Verified

  #1855290 30-Aug-2017 14:15
Send private message

Could be related to the latest Locky outbreak.

 

 

 

Quadruple the spam gone out with it. 

 

https://blog.fortinet.com/2017/08/17/locky-launches-a-more-massive-spam-campaign-with-new-lukitus-variant 


surfisup1000
5288 posts

Uber Geek


  #1855291 30-Aug-2017 14:16
Send private message

freitasm:

 

This huge (711 million records) leak would explain some email being sent from people's addresses and it contains email, password and SMTP server. 

 

I commented on there - Troy's Have I been pwned service is great but it's getting harder now to manage passwords. If you have a website leak and know the source you know where to change the password but with leaks that are username + password then it's harder to know where to change. And since he (rightly) do not disclose the passwords in the dumps then those already using unique passwords have a harder time. 

 

It seems we have to start using unique email + unique passwords to be able to better manage security. Those email aliases or emails with "+" in the address come handy here.

 

I recommend subscribing to the notification service at Have I been pwned so you receive notifications of leaks.

 

 

Email as we know it today is quite broken. 

 

 


Inphinity
2780 posts

Uber Geek


  #1855300 30-Aug-2017 14:51
Send private message

dryburn:

 

Does Troy's Have I been pwned service have a list of breached data content and then run that against the email you enter?

 

 

Yes, he maintains a DB based on leaked / breached lists of data and uses it to search against


kryptonjohn
2523 posts

Uber Geek

Lifetime subscriber

  #1855303 30-Aug-2017 15:07
Send private message

freitasm:

 

This huge (711 million records) leak would explain some email being sent from people's addresses and it contains email, password and SMTP server. 

 

I commented on there - Troy's Have I been pwned service is great but it's getting harder now to manage passwords. If you have a website leak and know the source you know where to change the password but with leaks that are username + password then it's harder to know where to change. And since he (rightly) do not disclose the passwords in the dumps then those already using unique passwords have a harder time. 

 

It seems we have to start using unique email + unique passwords to be able to better manage security. Those email aliases or emails with "+" in the address come handy here.

 

I recommend subscribing to the notification service at Have I been pwned so you receive notifications of leaks.

 

 

Two of my emails were found on Troys! But I now use LastPass to manage passwords, and I can check the dates that passwords were last change and confirm they were changed subsequent to the reported breaches.

 

Lastpass is fantastic - I really don't know how I managed without it. Actually I do know - I used to use the same passwords on dozens of different sites which is a no-no but the alternative is to write them down somewhere which is also a no-no. The other thing Lastpass does well is it's security check - it will tell you about sites that have weak passwords or passwords that are similar to passwords for other sites.

 

 

 

 

 

 

 

 

 

 


michaelmurfy
meow
13240 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #1855334 30-Aug-2017 15:42
Send private message

@kyhwana2 have a look at Authy (https://authy.com/) - very good and has device sync.





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


mdf

mdf
3513 posts

Uber Geek

Trusted

  #1855338 30-Aug-2017 15:50
Send private message

michaelmurfy:

@kyhwana2 have a look at Authy (https://authy.com/) - very good and has device sync.



As does Lastpass Authenticator (also totp compliant). I really like the push to authenticate option.

kyhwana2
2566 posts

Uber Geek


  #1855377 30-Aug-2017 16:42
Send private message

michaelmurfy:

@kyhwana2 have a look at Authy (https://authy.com/) - very good and has device sync.

 

 

Authy requires a smartphone/mobile number (to auth for the app install etc) tho, and someone mentioned they don't have one..

freitasm

BDFL - Memuneh
79257 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1855393 30-Aug-2017 16:47
Send private message

@mdf:

 

michaelmurfy:

 

kyhwana2 have a look at Authy (https://authy.com/) - very good and has device sync.

 



As does Lastpass Authenticator (also totp compliant). I really like the push to authenticate option.

 

The problem with using LastPass authenticator is that you then have BOTH your password AND your second authentication factor in the same platform. If LastPass is compromised (or your LastPass account is compromised by phishing) then the Bad Guy (TM) has all the keys needed to access all your accounts.

 

Keep it separate.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.