Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.security > #1341 > unrolled thread
| Started by | c186282 <c186282@nnada.net> |
|---|---|
| First post | 2025-10-27 21:02 -0400 |
| Last post | 2025-10-28 21:41 -0400 |
| Articles | 4 — 3 participants |
Back to article view | Back to alt.security
Giant GMail Hack FINALLY Revealed c186282 <c186282@nnada.net> - 2025-10-27 21:02 -0400
Re: Giant GMail Hack FINALLY Revealed Tom Mix <tommix@dev.null> - 2025-10-28 20:38 +0000
Re: Giant GMail Hack FINALLY Revealed The World of Izz <jfwalby@gmaill.com> - 2025-10-28 17:25 -0500
Re: Giant GMail Hack FINALLY Revealed c186282 <c186282@nnada.net> - 2025-10-28 21:41 -0400
| From | c186282 <c186282@nnada.net> |
|---|---|
| Date | 2025-10-27 21:02 -0400 |
| Subject | Giant GMail Hack FINALLY Revealed |
| Message-ID | <LqKdnbnP4_CJi530nZ2dnZfqnPSdnZ2d@giganews.com> |
https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183-MILLION-passwords-data-breach.html The incident occurred in April but has only just been disclosed Gmail users have been urged to check their accounts after it was revealed that more than 183 million passwords were stolen in a data breach. Australian cyber expert Troy Hunt, who revealed the incident, called it a 'vast corpus' of breached data, which totals 3.5 terrabytes. To put that into perspective, that's the equivalent to 875 full-length HD movies. According to Mr Hunt, 'all the major providers have email addresses in there' – so not just Gmail, but Outlook, Yahoo and others too. 'They're from everywhere you could imagine, but Gmail always features heavily,' Hunt told the Daily Mail. . . . I've been saying ... the current online-biz model is NO LONGER SAFE. And don't send Goog yer fingerprints either, then the hacks/Vlad will have THOSE too. Biometrics are only as secure as the database holding them and these days, well ...... When's the last time you actually WENT to your bank ? Does anyone there remember your face ?
[toc] | [next] | [standalone]
| From | Tom Mix <tommix@dev.null> |
|---|---|
| Date | 2025-10-28 20:38 +0000 |
| Message-ID | <slrn10g2ae8.14toi.tommix@devnull.org> |
| In reply to | #1341 |
On 2025-10-28, c186282 <c186282@nnada.net> wrote: > https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183-MILLION-passwords-data-breach.html > > The incident occurred in April but has only just been disclosed > > Gmail users have been urged to check their accounts after it > was revealed that more than 183 million passwords were stolen > in a data breach. > > Australian cyber expert Troy Hunt, who revealed the incident, > called it a 'vast corpus' of breached data, which totals > 3.5 terrabytes. > > To put that into perspective, that's the equivalent to 875 > full-length HD movies. > > According to Mr Hunt, 'all the major providers have email > addresses in there' – so not just Gmail, but Outlook, > Yahoo and others too. > > 'They're from everywhere you could imagine, but Gmail > always features heavily,' Hunt told the Daily Mail. > > . . . > > I've been saying ... the current online-biz model > is NO LONGER SAFE. > > And don't send Goog yer fingerprints either, then > the hacks/Vlad will have THOSE too. Biometrics > are only as secure as the database holding them > and these days, well ...... > > When's the last time you actually WENT to your > bank ? Does anyone there remember your face ? > You’re not wrong to be skeptical — the “trust the cloud” model has always relied on the hope that massive databases will stay sealed, and that’s been proven false again and again. Centralized storage of credentials, biometrics, and personal data is a goldmine for attackers — and the bigger the company, the juicier the target. This isn’t even a “hack Google” event so much as an ecosystem failure. The breach likely involved credential dumps from dozens of compromised sites that people reused passwords on, which then get lumped together into these monster datasets. It’s a reminder that *security by scale* isn’t security at all — it’s just a bigger mess when it fails. And yes, biometrics are absolutely not magic. Once your fingerprint or face data leaks, you can’t change it like a password. Combine that with how rarely people visit a physical branch anymore, and you’ve got a system that’s convenient but completely impersonal — and vulnerable the second the digital façade cracks. The moral: use unique passwords, MFA, and assume every large provider is a breach waiting to happen. The business model’s not broken because of bad tech — it’s broken because convenience keeps winning over caution. -- Tom Mix
[toc] | [prev] | [next] | [standalone]
| From | The World of Izz <jfwalby@gmaill.com> |
|---|---|
| Date | 2025-10-28 17:25 -0500 |
| Message-ID | <mmcu6iFpjdqU3@mid.individual.net> |
| In reply to | #1342 |
Tom Mix wrote: > On 2025-10-28, c186282 <c186282@nnada.net> wrote: >> https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183-MILLION-passwords-data-breach.html >> >> The incident occurred in April but has only just been disclosed >> >> Gmail users have been urged to check their accounts after it >> was revealed that more than 183 million passwords were stolen >> in a data breach. >> >> Australian cyber expert Troy Hunt, who revealed the incident, >> called it a 'vast corpus' of breached data, which totals >> 3.5 terrabytes. >> >> To put that into perspective, that's the equivalent to 875 >> full-length HD movies. >> >> According to Mr Hunt, 'all the major providers have email >> addresses in there' – so not just Gmail, but Outlook, >> Yahoo and others too. >> >> 'They're from everywhere you could imagine, but Gmail >> always features heavily,' Hunt told the Daily Mail. >> >> . . . >> >> I've been saying ... the current online-biz model >> is NO LONGER SAFE. >> >> And don't send Goog yer fingerprints either, then >> the hacks/Vlad will have THOSE too. Biometrics >> are only as secure as the database holding them >> and these days, well ...... >> >> When's the last time you actually WENT to your >> bank ? Does anyone there remember your face ? >> > > You’re not wrong to be skeptical — the “trust the cloud” model has always > relied on the hope that massive databases will stay sealed, and that’s been > proven false again and again. Centralized storage of credentials, biometrics, > and personal data is a goldmine for attackers — and the bigger the company, > the juicier the target. > > This isn’t even a “hack Google” event so much as an ecosystem failure. The > breach likely involved credential dumps from dozens of compromised sites that > people reused passwords on, which then get lumped together into these monster > datasets. It’s a reminder that *security by scale* isn’t security at all — it’s > just a bigger mess when it fails. > > And yes, biometrics are absolutely not magic. Once your fingerprint or face > data leaks, you can’t change it like a password. Combine that with how rarely > people visit a physical branch anymore, and you’ve got a system that’s > convenient but completely impersonal — and vulnerable the second the digital > façade cracks. > > The moral: use unique passwords, MFA, and assume every large provider is a > breach waiting to happen. The business model’s not broken because of bad tech > — it’s broken because convenience keeps winning over caution. > Jonathan Sylvester used his middle name with the number 1 appended every time he set his password during 2004. -- collaborate !believe protect !hunt
[toc] | [prev] | [next] | [standalone]
| From | c186282 <c186282@nnada.net> |
|---|---|
| Date | 2025-10-28 21:41 -0400 |
| Message-ID | <Q-ycnTaXfckw7Zz0nZ2dnZfqnPcAAAAA@giganews.com> |
| In reply to | #1343 |
On 10/28/25 18:25, The World of Izz wrote: > Tom Mix wrote: >> On 2025-10-28, c186282 <c186282@nnada.net> wrote: >>> https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183- >>> MILLION-passwords-data-breach.html >>> >>> The incident occurred in April but has only just been disclosed >>> >>> Gmail users have been urged to check their accounts after it >>> was revealed that more than 183 million passwords were stolen >>> in a data breach. >>> >>> Australian cyber expert Troy Hunt, who revealed the incident, >>> called it a 'vast corpus' of breached data, which totals >>> 3.5 terrabytes. >>> >>> To put that into perspective, that's the equivalent to 875 >>> full-length HD movies. >>> >>> According to Mr Hunt, 'all the major providers have email >>> addresses in there' – so not just Gmail, but Outlook, >>> Yahoo and others too. >>> >>> 'They're from everywhere you could imagine, but Gmail >>> always features heavily,' Hunt told the Daily Mail. >>> >>> . . . >>> >>> I've been saying ... the current online-biz model >>> is NO LONGER SAFE. >>> >>> And don't send Goog yer fingerprints either, then >>> the hacks/Vlad will have THOSE too. Biometrics >>> are only as secure as the database holding them >>> and these days, well ...... >>> >>> When's the last time you actually WENT to your >>> bank ? Does anyone there remember your face ? >>> >> >> You’re not wrong to be skeptical — the “trust the cloud” model has always >> relied on the hope that massive databases will stay sealed, and that’s >> been >> proven false again and again. Centralized storage of credentials, >> biometrics, >> and personal data is a goldmine for attackers — and the bigger the >> company, >> the juicier the target. >> >> This isn’t even a “hack Google” event so much as an ecosystem failure. >> The >> breach likely involved credential dumps from dozens of compromised >> sites that >> people reused passwords on, which then get lumped together into these >> monster >> datasets. It’s a reminder that *security by scale* isn’t security at >> all — it’s >> just a bigger mess when it fails. >> >> And yes, biometrics are absolutely not magic. Once your fingerprint or >> face >> data leaks, you can’t change it like a password. Combine that with how >> rarely >> people visit a physical branch anymore, and you’ve got a system that’s >> convenient but completely impersonal — and vulnerable the second the >> digital >> façade cracks. >> >> The moral: use unique passwords, MFA, and assume every large provider >> is a >> breach waiting to happen. The business model’s not broken because of >> bad tech >> — it’s broken because convenience keeps winning over caution. >> > Jonathan Sylvester used his middle name with the number 1 appended every > time he set his password during 2004. Who the hell is Jonathan Sylvester ? By even recent reports, still the #1 popular password is "password" :-) Complexity rules oft require "Password-1" as the alt. Most sane people will keep cross-account passwords 'similar' enough so they can remember, or at least guess quick, but exactly the same PW for everything IS a terrible idea. Joe Average is unlikely to get major individual hack attention - one fail and they'll move on to the next victim. Bigger biz/govt accounts though ... Back when I was setting up servers, I'd always set the standard services like SSH, FTP, VNC and such to a non-standard port value. Sometimes you could actually catch the hacks in progress ... they'd scan the standards and then move on - why waste the time looking at, analyzing, everything ? Plenty of fish in the sea. As for e-mail and a few basics, you MIGHT look into some of the smaller-but-good providers instead of something in close orbit of Goog and big buddies. Goog is the Big Giant Target the evil boyz just can't ignore, the mother-load if they score. Oh, do not adopt the "Well, stupid people deserve to get burned !" mindset. There are mass MASS quantities of stupid people and if they go down they'll drag YOU down with them.
[toc] | [prev] | [standalone]
Back to top | Article view | alt.security
csiph-web