• Hey Guest. Check out your NeoGAF Wrapped 2025 results here!

2+ million facebook, yahoo, google passwords posted online

Status
Not open for further replies.
http://www.bbc.co.uk/news/technology-25213846

More than two million stolen passwords used for sites such as Facebook, Google and Yahoo and other web services have been posted online.

The details had probably been uploaded by a criminal gang, security experts said.

It is suspected the data was taken from computers infected with malicious software that logged key presses.

In a blog post outlining its findings, the team said it believed the passwords had been harvested by a large botnet - dubbed Pony - that had scooped up information from thousands of infected computers worldwide.

Original blog post:
http://blog.spiderlabs.com/2013/12/...ny.html?utm_source=dlvr.it&utm_medium=twitter
 
Do they know the users who use said passwords? If so, damn users better change their stuff fast. If not, have fun wasting your time using the same passwords until it finally works for someone.
 
2 factor authentication mo'fuckaaaaaa


edit: oh sweet I'm in the "excellent" bracket, the hackers like me.
 
hunter2. Damnit. I've been duped!

People who post 12345678 as password usually don't give a fuck if its stolen. I had that for my Yahoo account until I had to use it for GAF NHL League, and I changed it... except when they give a fuck and its stolen, then its sad.
 
123456 is at least slightly better than your password being..."password"

Why do you use that?

"its easy to remember, it says my password right there."

Yes, a real human being i know literally said that. Not it was not a toddler, yes it was a grown up man.
 
Two step verification for life. Sure sometimes it's a hassle, but whenever some doofus tries anything funny I get a text.
 
Trustwave Spiderlabs is pretty awesome stuff. I work for a company related in some way to them, they release some pretty interesting blogs and informational posts. :)
 
2 Step Authentication on Gmail + Backup Phone in addition to mobile phone + Printed Backup Codes = Fuck yeah.
 
6a0168e94917b4970c019b01abc974970d-500wi


I'm so done.
 
Anyone know where the list actually is, or at least a list of compromised users? I highly doubt I'm on it, but I always want to check these kinds of things.
 
I just turned on 2 step verification on GMail, but I had a thought.

What if you say, only had a laptop as a verified computer, and someone stole your phone and laptop? From another computer, could you still log into your Google account to both access your GMail and remotely lock/wipe your phone?
 
Apparently these passwords are collected using a trojan. So you should double-check with your anti-virus to see if you're infected and reset ALL your passwords before it's too late and somebody else changes them all.
 
So keylogger huh? I don't really login to accounts outside of my house so I doubt I'm compromised. My passwords are different per account and are alpha-numeric.
 
Status
Not open for further replies.
Top Bottom