• Register
  • TOS
  • Privacy
  • @NeoGAF

cartoon_soldier
Member
(Yesterday, 10:46 PM)
http://www.bbc.co.uk/news/technology-25213846

More than two million stolen passwords used for sites such as Facebook, Google and Yahoo and other web services have been posted online.

The details had probably been uploaded by a criminal gang, security experts said.

It is suspected the data was taken from computers infected with malicious software that logged key presses.

In a blog post outlining its findings, the team said it believed the passwords had been harvested by a large botnet - dubbed Pony - that had scooped up information from thousands of infected computers worldwide.

Original blog post:
http://blog.spiderlabs.com/2013/12/l...medium=twitter
Speedy Blue Dude
Member
(Yesterday, 10:48 PM)
Speedy Blue Dude's Avatar
Do they know the users who use said passwords? If so, damn users better change their stuff fast. If not, have fun wasting your time using the same passwords until it finally works for someone.
Cosmo Clock 21
Member
(Yesterday, 10:48 PM)
Cosmo Clock 21's Avatar
God damn bronies.
Bay Maximus
Member
(Yesterday, 10:49 PM)
Bay Maximus's Avatar
Any word on GAF passwords?
SRG01
Member
(Yesterday, 10:49 PM)
SRG01's Avatar
SMH at 123456. Seriously?
kick51
Member
(Yesterday, 10:49 PM)
kick51's Avatar
2 factor authentication mo'fuckaaaaaa


edit: oh sweet I'm in the "excellent" bracket, the hackers like me.
Last edited by kick51; Yesterday at 10:52 PM.
stuminus3
Never buying another games console. Ever.
(Yesterday, 10:49 PM)
stuminus3's Avatar
Incoming flurry of imbeciles on my Facebook freaking out because they've been 'hacked'.
samus i am
Member
(Yesterday, 10:50 PM)
samus i am's Avatar
Ugh, I don't want to have to change my password.
Espresso
Member
(Yesterday, 10:51 PM)
Mac for life.
Guy.brush
Junior Member
(Yesterday, 10:52 PM)
Guy.brush's Avatar
Is the US nuclear launch password on it too?
That would be 00000000
jersoc
Member
(Yesterday, 10:53 PM)
if you haven't already, now would be a good time for 2 step on your google account.
Origami Superman
Member
(Yesterday, 10:53 PM)
Origami Superman's Avatar
I hate having to look at my own Facebook feed most of the time, why would I want to see any other saps.
Protein
Member
(Yesterday, 10:54 PM)
Protein's Avatar
I'm sure the NSA will bring these people to justice.
NotTheGuyYouKill
Member
(Yesterday, 10:54 PM)
NotTheGuyYouKill's Avatar
How do we know if we're at risk?
UraMallas
Member
(Yesterday, 10:54 PM)
UraMallas's Avatar

Originally Posted by SRG01

SMH at 123456. Seriously?

That's amazing - that's the same combination I have on my luggage.
shagg_187
lapdance transform pants
(Yesterday, 10:55 PM)
shagg_187's Avatar
hunter2. Damnit. I've been duped!

People who post 12345678 as password usually don't give a fuck if its stolen. I had that for my Yahoo account until I had to use it for GAF NHL League, and I changed it... except when they give a fuck and its stolen, then its sad.
Last edited by shagg_187; Yesterday at 11:00 PM.
Hellsing321
Member
(Yesterday, 10:57 PM)
Hellsing321's Avatar
Over 1000 people just had 1 as their password...
Agent AA1
Junior Member
(Yesterday, 10:57 PM)
Agent AA1's Avatar

Originally Posted by SRG01

SMH at 123456. Seriously?

Dang!!! I have to change my password now.

Seriously though, thats sad.
Into
Member
(Yesterday, 10:58 PM)
Into's Avatar
123456 is at least slightly better than your password being..."password"

Why do you use that?

"its easy to remember, it says my password right there."

Yes, a real human being i know literally said that. Not it was not a toddler, yes it was a grown up man.
ComputerMKII
Member
(Yesterday, 11:00 PM)
ComputerMKII's Avatar

Originally Posted by kick51

2 factor authentication mo'fuckaaaaaa


edit: oh sweet I'm in the "excellent" bracket, the hackers like me.

Thanks for reminding me to activate that feature.
Last edited by ComputerMKII; Yesterday at 11:04 PM.
bodyboarder
Member
(Yesterday, 11:00 PM)
bodyboarder's Avatar

Originally Posted by samus i am

Ugh, I don't want to have to change my password.

You used password didn't you.
Danielsan
Member
(Yesterday, 11:02 PM)
Danielsan's Avatar
Two step verification for life. Sure sometimes it's a hassle, but whenever some doofus tries anything funny I get a text.
Starviper
Member
(Yesterday, 11:02 PM)
Starviper's Avatar
Trustwave Spiderlabs is pretty awesome stuff. I work for a company related in some way to them, they release some pretty interesting blogs and informational posts. :)
Kajigger
Member
(Yesterday, 11:03 PM)
Kajigger's Avatar
If your password is 123456, 000000, 111111 or any other thing like that you deserve to have someone steal it.
Stat Flow
He gonna cry in the car
(Yesterday, 11:03 PM)
Stat Flow's Avatar
2 Step Authentication on Gmail + Backup Phone in addition to mobile phone + Printed Backup Codes = Fuck yeah.
adj_noun
Member
(Yesterday, 11:03 PM)
adj_noun's Avatar

Originally Posted by bodyboarder

You used password didn't you.

HA! I never use password! :D

Password123 for life!
Vyer
Member
(Yesterday, 11:06 PM)
Vyer's Avatar

Originally Posted by SRG01

SMH at 123456. Seriously?

I've got the same combination on my luggage.
Emwitus
car flags....
car flags everywhere
(Yesterday, 11:07 PM)
Emwitus's Avatar

Originally Posted by Vyer

I've got the same combination on my luggage.

That's what she said
Vyer
Member
(Yesterday, 11:09 PM)
Vyer's Avatar

Originally Posted by Emwitus

That's what she said

Don't call me Shirley.
freenudemacusers
Member
(Yesterday, 11:10 PM)
freenudemacusers's Avatar
jokes on them, I use 654321 for everything.
flippedb
Member
(Yesterday, 11:18 PM)
flippedb's Avatar
I'll change my GAF password to "anal pleasure with pink dildo"
Vyroxis
Member
(Yesterday, 11:23 PM)
Vyroxis's Avatar
Where are these lists posted? I wanna see if any of my friends are on the list so I can laugh at them.
Mariolee
Member
(Yesterday, 11:25 PM)
Mariolee's Avatar


I'm so done.
samus i am
Member
(Yesterday, 11:26 PM)
samus i am's Avatar

Originally Posted by bodyboarder

You used password didn't you.

Changed it to 123456. The coast is clear.
slit
Member
(Yesterday, 11:29 PM)
slit's Avatar
Yep, I heard about this. I work in cyber security so I'll be hearing about it for awhile.
Last edited by slit; Today at 12:53 AM.
Earthstrike
Member
(Yesterday, 11:29 PM)
Earthstrike's Avatar
Anyone know where the list actually is, or at least a list of compromised users? I highly doubt I'm on it, but I always want to check these kinds of things.
la flama blanca
Member
(Yesterday, 11:29 PM)
la flama blanca's Avatar
Mostly from the Netherlands though if I read correctly.

Originally Posted by Earthstrike

Anyone know where the list actually is, or at least a list of compromised users? I highly doubt I'm on it, but I always want to check these kinds of things.


Yes I would like an awesome brute force list as well...lol
SamVimes
Member
(Yesterday, 11:29 PM)
SamVimes's Avatar
Balphon
Member
(Yesterday, 11:30 PM)
Balphon's Avatar
Someone really had it out for the Netherlands.
CornBurrito
Member
(Yesterday, 11:34 PM)
CornBurrito's Avatar
So I guess it is time to change my passwords :[
Tenacious-V
Thinks his PR is better than yours.
(Yesterday, 11:38 PM)
Tenacious-V's Avatar

Originally Posted by la flama blanca

Mostly from the Netherlands though if I read correctly.

Netherlands was a hub, maybe like a vpn server or something, to hide their tracks. The link says that the majority of the ones from the Netherlands came from the same IP address.
Choppasmith
Member
(Yesterday, 11:40 PM)
Choppasmith's Avatar

Originally Posted by Cosmo Clock 21

God damn bronies.

???


Edit: Ah, I see where you're coming from now.
Last edited by Choppasmith; Yesterday at 11:43 PM.
besada
PoliGAF Co-Champion
(Yesterday, 11:41 PM)
besada's Avatar

Originally Posted by flippedb

I'll change my GAF password to "anal pleasure with pink dildo"

It's already being used.

Or so I hear.
SixFourMike
Member
(Yesterday, 11:41 PM)
I just turned on 2 step verification on GMail, but I had a thought.

What if you say, only had a laptop as a verified computer, and someone stole your phone and laptop? From another computer, could you still log into your Google account to both access your GMail and remotely lock/wipe your phone?
undu
Member
(Yesterday, 11:43 PM)
undu's Avatar
Apparently these passwords are collected using a trojan. So you should double-check with your anti-virus to see if you're infected and reset ALL your passwords before it's too late and somebody else changes them all.
Stumpokapow
listen to the mad man
(Yesterday, 11:45 PM)
Stumpokapow's Avatar
14+ character four character types passwords = top one hundredth of one percent of passwords.
jett
Member
(Yesterday, 11:50 PM)
jett's Avatar
Two-step verification bitches. Feeling safe.
strafer
member
(Yesterday, 11:52 PM)
strafer's Avatar
fucking hell, I just changed passwords last week.
MilesWebber
double the fail
(Yesterday, 11:55 PM)
MilesWebber's Avatar
the fuck is a chocolate teapot? I want one.
jsnepo
Member
(Today, 12:01 AM)
jsnepo's Avatar
So keylogger huh? I don't really login to accounts outside of my house so I doubt I'm compromised. My passwords are different per account and are alpha-numeric.

Thread Tools