Calgarypuck Forums - The Unofficial Calgary Flames Fan Community

Go Back   Calgarypuck Forums - The Unofficial Calgary Flames Fan Community > Main Forums > The Off Topic Forum > Tech Talk
Register Forum Rules FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Search this Thread
Old 09-10-2014, 12:00 PM   #1
photon
The new goggles also do nothing.
 
photon's Avatar
 
Join Date: Oct 2001
Location: Calgary
Exp:
Default 5 Million Gmail Passwords Leaked

http://lifehacker.com/5-million-gmai...now-1632983265

Enable 2 factor authentication!
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
photon is offline   Reply With Quote
The Following 2 Users Say Thank You to photon For This Useful Post:
Old 09-10-2014, 12:31 PM   #2
Regulator75
Franchise Player
 
Regulator75's Avatar
 
Join Date: Oct 2001
Location: Behind Nikkor Glass
Exp:
Default

All good here. No leakage.
__________________

More photos on Flickr
Regulator75 is offline   Reply With Quote
Old 09-10-2014, 12:34 PM   #3
Hemi-Cuda
wins 10 internets
 
Hemi-Cuda's Avatar
 
Join Date: Feb 2006
Location: slightly to the left
Exp:
Default

It wasn't gmail passwords leaked, it was passwords for various other sites that used email addresses as login names and someone cut out everything except the gmail addresses. So unless you use the same password for gmail that you use for everything else you sign up for (don't be that person) there's no issue
Hemi-Cuda is offline   Reply With Quote
The Following 2 Users Say Thank You to Hemi-Cuda For This Useful Post:
Old 09-10-2014, 12:44 PM   #4
Barnes
Franchise Player
 
Barnes's Avatar
 
Join Date: Aug 2005
Location: Violating Copyrights
Exp:
Default

Quote:
Originally Posted by Hemi-Cuda View Post
It wasn't gmail passwords leaked, it was passwords for various other sites that used email addresses as login names and someone cut out everything except the gmail addresses. So unless you use the same password for gmail that you use for everything else you sign up for (don't be that person) there's no issue
Mine was leaked but the password is not the one I use for gmail. Wonder where these are from?
Barnes is offline   Reply With Quote
Old 09-10-2014, 01:05 PM   #5
Dion
Not a casual user
 
Dion's Avatar
 
Join Date: Mar 2006
Location: A simple man leading a complicated life....
Exp:
Default

Mine wasn't leaked.
__________________
Dion is offline   Reply With Quote
Old 09-10-2014, 01:52 PM   #6
Regulator75
Franchise Player
 
Regulator75's Avatar
 
Join Date: Oct 2001
Location: Behind Nikkor Glass
Exp:
Default

Quote:
Originally Posted by Barnes View Post
Wonder where these are from?
Russian mail order wives websites...

By the way, did you end up choosing Svetlana or Olga?
__________________

More photos on Flickr
Regulator75 is offline   Reply With Quote
Old 09-10-2014, 04:09 PM   #7
Barnes
Franchise Player
 
Barnes's Avatar
 
Join Date: Aug 2005
Location: Violating Copyrights
Exp:
Default

Quote:
Originally Posted by Regulator75 View Post
Russian mail order wives websites...

By the way, did you end up choosing Svetlana or Olga?
Svetlana. She's held up in customs. Something about a manditory quarantine period.
Barnes is offline   Reply With Quote
The Following User Says Thank You to Barnes For This Useful Post:
Old 09-10-2014, 04:15 PM   #8
Igster
Lifetime Suspension
 
Join Date: Jan 2013
Exp:
Default

Changed my password anyway. Just to be safe. Can't check to see if mine was leaked, but not a bad idea to change every once in a while anyway.
Igster is offline   Reply With Quote
Old 09-10-2014, 04:16 PM   #9
DownhillGoat
Franchise Player
 
DownhillGoat's Avatar
 
Join Date: Jan 2010
Exp:
Default

Quote:
Originally Posted by photon View Post
Enable 2 factor authentication!
So I enabled that. Did I just make life a total pain in the *** for travelling?
DownhillGoat is offline   Reply With Quote
Old 09-10-2014, 04:25 PM   #10
Resolute 14
In the Sin Bin
 
Resolute 14's Avatar
 
Join Date: Jan 2003
Exp:
Default

The scary thing about the screenshot in the story is that the people obviously used their own phone numbers. May as well have just used their SIN/SSN.

Kind of a shame that the list was taken down. Would have been fun to point and laugh at some of the passwords.
Resolute 14 is offline   Reply With Quote
Old 09-10-2014, 04:45 PM   #11
photon
The new goggles also do nothing.
 
photon's Avatar
 
Join Date: Oct 2001
Location: Calgary
Exp:
Default

Quote:
Originally Posted by kunkstyle View Post
So I enabled that. Did I just make life a total pain in the *** for travelling?
Yeah if you can't get SMSs then it might be a problem if you use it from a completely new computer.

If you have your phone I think you can generate authentication codes with this app:

https://support.google.com/accounts/answer/1066447

Never used it though.

EDIT: You can also print out backup codes and carry them with you: https://support.google.com/accounts/..._topic=2784804
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
photon is offline   Reply With Quote
The Following 2 Users Say Thank You to photon For This Useful Post:
Old 09-10-2014, 04:47 PM   #12
DownhillGoat
Franchise Player
 
DownhillGoat's Avatar
 
Join Date: Jan 2010
Exp:
Default

Quote:
Originally Posted by photon View Post
Yeah if you can't get SMSs then it might be a problem if you use it from a completely new computer.
Thanks. I just downloaded the app and you can print 10 backup codes apparently.

The day before a big trip was likely not the best time to try it out...
DownhillGoat is offline   Reply With Quote
Old 09-10-2014, 04:48 PM   #13
photon
The new goggles also do nothing.
 
photon's Avatar
 
Join Date: Oct 2001
Location: Calgary
Exp:
Default

Or might make the trip better, enforced vacation from email!
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
photon is offline   Reply With Quote
Old 09-10-2014, 10:14 PM   #14
Drury18
Franchise Player
 
Drury18's Avatar
 
Join Date: Apr 2003
Exp:
Default

Quote:
Originally Posted by photon View Post

If you have your phone I think you can generate authentication codes with this app:

https://support.google.com/accounts/answer/1066447

Never used it though.

I have and use that app for Gmail and Facebook now. Very simple and easy to use. It's like using a RSA Token. The app generates a code that is valid for I believe 3 minutes. You can see a countdown clock and so long as you enter the code before the clock is up, it will be valid.

Setup is very simple. You scan the QR code generated by Gmail when you enable the two step process and the generator populates with the information and starts producing numbers immediately.
Drury18 is offline   Reply With Quote
The Following 2 Users Say Thank You to Drury18 For This Useful Post:
Old 09-11-2014, 08:57 AM   #15
DownhillGoat
Franchise Player
 
DownhillGoat's Avatar
 
Join Date: Jan 2010
Exp:
Default

Quote:
Originally Posted by photon View Post
Or might make the trip better, enforced vacation from email!
Ha not if I have to get to trip itineraries.
DownhillGoat is offline   Reply With Quote
Old 09-13-2014, 08:57 AM   #16
WilsonFourTwo
First Line Centre
 
WilsonFourTwo's Avatar
 
Join Date: Apr 2009
Location: Calgary.
Exp:
Default

An old gaming account of mine (that I haven't used in years and years and years) got hacked recently, prompting me to change the password on all my online accounts.

Wanna talk PITA.....try remembering every little thing you've logged into over the past 5 years. Wowzers. Turns out the timing couldn't have been better.
__________________

WilsonFourTwo is offline   Reply With Quote
Old 09-16-2014, 08:31 AM   #17
Flames89
First Line Centre
 
Flames89's Avatar
 
Join Date: Aug 2003
Location: Toronto, ON
Exp:
Default

Does anyone use those 1password type services?
Flames89 is offline   Reply With Quote
Old 09-16-2014, 08:42 AM   #18
photon
The new goggles also do nothing.
 
photon's Avatar
 
Join Date: Oct 2001
Location: Calgary
Exp:
Default

Yup lots of people here have discussed them and others like it at one point or another, I think they're almost a requirement these days.

I personally use KeePass which is an application rather than an online service, just because in principle an online service is a bigger hacking target than my personal PC (and I think there's been at least one major online password storage place that was hacked, though if you had a strong password your info was still secure).

And attacking passwords has never been easier, if a hacker gets a copy of the user database where passwords are stored they can often try billions of passwords a second with off the shelf video cards, so having a long password is the best defence, and the best way to do that is something to remember the passwords and have different passwords for everything.

EDIT: Oh, is 1Password an app only as well? I thought it was an online service.
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
photon is offline   Reply With Quote
The Following User Says Thank You to photon For This Useful Post:
Old 09-16-2014, 12:32 PM   #19
DownhillGoat
Franchise Player
 
DownhillGoat's Avatar
 
Join Date: Jan 2010
Exp:
Default

Quote:
Originally Posted by photon View Post
EDIT: Oh, is 1Password an app only as well? I thought it was an online service.
App only but it allows the option to upload the passkey to your dropbox account.

Got it after the PS3/sony online breach. That program is worth it's weight in gold. Although I'm still slightly hesitant about storing it in dropbox.
DownhillGoat is offline   Reply With Quote
The Following User Says Thank You to DownhillGoat For This Useful Post:
Old 09-16-2014, 02:41 PM   #20
photon
The new goggles also do nothing.
 
photon's Avatar
 
Join Date: Oct 2001
Location: Calgary
Exp:
Default

I put my KeePass file in Dropbox, my password is pretty long (like over 25 characters) and KeePass has a work factor in it so you can scale how long a computer takes to hash the password, reducing the # of guesses per second from billions to a couple makes it very difficult to crack.

KeePass can go further as well by using a public/private key as part of the encryption so you need the private key to decrypt the password file. On my computer it does like 16 million iterations of the hashing algorithm.
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
photon is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -6. The time now is 01:45 PM.

Calgary Flames
2024-25




Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright Calgarypuck 2021 | See Our Privacy Policy