Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.security > #1341 > unrolled thread

Giant GMail Hack FINALLY Revealed

Started byc186282 <c186282@nnada.net>
First post2025-10-27 21:02 -0400
Last post2025-10-28 21:41 -0400
Articles 4 — 3 participants

Back to article view | Back to alt.security


Contents

  Giant GMail Hack FINALLY Revealed c186282 <c186282@nnada.net> - 2025-10-27 21:02 -0400
    Re: Giant GMail Hack FINALLY Revealed Tom Mix <tommix@dev.null> - 2025-10-28 20:38 +0000
      Re: Giant GMail Hack FINALLY Revealed The World of Izz <jfwalby@gmaill.com> - 2025-10-28 17:25 -0500
        Re: Giant GMail Hack FINALLY Revealed c186282 <c186282@nnada.net> - 2025-10-28 21:41 -0400

#1341 — Giant GMail Hack FINALLY Revealed

Fromc186282 <c186282@nnada.net>
Date2025-10-27 21:02 -0400
SubjectGiant GMail Hack FINALLY Revealed
Message-ID<LqKdnbnP4_CJi530nZ2dnZfqnPSdnZ2d@giganews.com>
https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183-MILLION-passwords-data-breach.html

The incident occurred in April but has only just been disclosed

Gmail users have been urged to check their accounts after it
was revealed that more than 183 million passwords were stolen
in a data breach.

Australian cyber expert Troy Hunt, who revealed the incident,
called it a 'vast corpus' of breached data, which totals
3.5 terrabytes.

To put that into perspective, that's the equivalent to 875
full-length HD movies.

According to Mr Hunt, 'all the major providers have email
addresses in there' – so not just Gmail, but Outlook,
Yahoo and others too.

'They're from everywhere you could imagine, but Gmail
always features heavily,' Hunt told the Daily Mail.

. . .

   I've been saying ... the current online-biz model
   is NO LONGER SAFE.

   And don't send Goog yer fingerprints either, then
   the hacks/Vlad will have THOSE too. Biometrics
   are only as secure as the database holding them
   and these days, well ......

   When's the last time you actually WENT to your
   bank ? Does anyone there remember your face ?

[toc] | [next] | [standalone]


#1342

FromTom Mix <tommix@dev.null>
Date2025-10-28 20:38 +0000
Message-ID<slrn10g2ae8.14toi.tommix@devnull.org>
In reply to#1341
On 2025-10-28, c186282 <c186282@nnada.net> wrote:
> https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183-MILLION-passwords-data-breach.html
>
> The incident occurred in April but has only just been disclosed
>
> Gmail users have been urged to check their accounts after it
> was revealed that more than 183 million passwords were stolen
> in a data breach.
>
> Australian cyber expert Troy Hunt, who revealed the incident,
> called it a 'vast corpus' of breached data, which totals
> 3.5 terrabytes.
>
> To put that into perspective, that's the equivalent to 875
> full-length HD movies.
>
> According to Mr Hunt, 'all the major providers have email
> addresses in there' – so not just Gmail, but Outlook,
> Yahoo and others too.
>
> 'They're from everywhere you could imagine, but Gmail
> always features heavily,' Hunt told the Daily Mail.
>
> . . .
>
>    I've been saying ... the current online-biz model
>    is NO LONGER SAFE.
>
>    And don't send Goog yer fingerprints either, then
>    the hacks/Vlad will have THOSE too. Biometrics
>    are only as secure as the database holding them
>    and these days, well ......
>
>    When's the last time you actually WENT to your
>    bank ? Does anyone there remember your face ?
>

You’re not wrong to be skeptical — the “trust the cloud” model has always 
relied on the hope that massive databases will stay sealed, and that’s been 
proven false again and again. Centralized storage of credentials, biometrics, 
and personal data is a goldmine for attackers — and the bigger the company, 
the juicier the target.

This isn’t even a “hack Google” event so much as an ecosystem failure. The 
breach likely involved credential dumps from dozens of compromised sites that 
people reused passwords on, which then get lumped together into these monster 
datasets. It’s a reminder that *security by scale* isn’t security at all — it’s 
just a bigger mess when it fails.

And yes, biometrics are absolutely not magic. Once your fingerprint or face 
data leaks, you can’t change it like a password. Combine that with how rarely 
people visit a physical branch anymore, and you’ve got a system that’s 
convenient but completely impersonal — and vulnerable the second the digital 
façade cracks.

The moral: use unique passwords, MFA, and assume every large provider is a 
breach waiting to happen. The business model’s not broken because of bad tech 
— it’s broken because convenience keeps winning over caution.

-- 
Tom Mix

[toc] | [prev] | [next] | [standalone]


#1343

FromThe World of Izz <jfwalby@gmaill.com>
Date2025-10-28 17:25 -0500
Message-ID<mmcu6iFpjdqU3@mid.individual.net>
In reply to#1342
Tom Mix wrote:
> On 2025-10-28, c186282 <c186282@nnada.net> wrote:
>> https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183-MILLION-passwords-data-breach.html
>>
>> The incident occurred in April but has only just been disclosed
>>
>> Gmail users have been urged to check their accounts after it
>> was revealed that more than 183 million passwords were stolen
>> in a data breach.
>>
>> Australian cyber expert Troy Hunt, who revealed the incident,
>> called it a 'vast corpus' of breached data, which totals
>> 3.5 terrabytes.
>>
>> To put that into perspective, that's the equivalent to 875
>> full-length HD movies.
>>
>> According to Mr Hunt, 'all the major providers have email
>> addresses in there' – so not just Gmail, but Outlook,
>> Yahoo and others too.
>>
>> 'They're from everywhere you could imagine, but Gmail
>> always features heavily,' Hunt told the Daily Mail.
>>
>> . . .
>>
>>     I've been saying ... the current online-biz model
>>     is NO LONGER SAFE.
>>
>>     And don't send Goog yer fingerprints either, then
>>     the hacks/Vlad will have THOSE too. Biometrics
>>     are only as secure as the database holding them
>>     and these days, well ......
>>
>>     When's the last time you actually WENT to your
>>     bank ? Does anyone there remember your face ?
>>
> 
> You’re not wrong to be skeptical — the “trust the cloud” model has always
> relied on the hope that massive databases will stay sealed, and that’s been
> proven false again and again. Centralized storage of credentials, biometrics,
> and personal data is a goldmine for attackers — and the bigger the company,
> the juicier the target.
> 
> This isn’t even a “hack Google” event so much as an ecosystem failure. The
> breach likely involved credential dumps from dozens of compromised sites that
> people reused passwords on, which then get lumped together into these monster
> datasets. It’s a reminder that *security by scale* isn’t security at all — it’s
> just a bigger mess when it fails.
> 
> And yes, biometrics are absolutely not magic. Once your fingerprint or face
> data leaks, you can’t change it like a password. Combine that with how rarely
> people visit a physical branch anymore, and you’ve got a system that’s
> convenient but completely impersonal — and vulnerable the second the digital
> façade cracks.
> 
> The moral: use unique passwords, MFA, and assume every large provider is a
> breach waiting to happen. The business model’s not broken because of bad tech
> — it’s broken because convenience keeps winning over caution.
> 
Jonathan Sylvester used his middle name with the number 1 appended every 
time he set his password during 2004.

-- 
collaborate !believe protect !hunt

[toc] | [prev] | [next] | [standalone]


#1344

Fromc186282 <c186282@nnada.net>
Date2025-10-28 21:41 -0400
Message-ID<Q-ycnTaXfckw7Zz0nZ2dnZfqnPcAAAAA@giganews.com>
In reply to#1343
On 10/28/25 18:25, The World of Izz wrote:
> Tom Mix wrote:
>> On 2025-10-28, c186282 <c186282@nnada.net> wrote:
>>> https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183- 
>>> MILLION-passwords-data-breach.html
>>>
>>> The incident occurred in April but has only just been disclosed
>>>
>>> Gmail users have been urged to check their accounts after it
>>> was revealed that more than 183 million passwords were stolen
>>> in a data breach.
>>>
>>> Australian cyber expert Troy Hunt, who revealed the incident,
>>> called it a 'vast corpus' of breached data, which totals
>>> 3.5 terrabytes.
>>>
>>> To put that into perspective, that's the equivalent to 875
>>> full-length HD movies.
>>>
>>> According to Mr Hunt, 'all the major providers have email
>>> addresses in there' – so not just Gmail, but Outlook,
>>> Yahoo and others too.
>>>
>>> 'They're from everywhere you could imagine, but Gmail
>>> always features heavily,' Hunt told the Daily Mail.
>>>
>>> . . .
>>>
>>>     I've been saying ... the current online-biz model
>>>     is NO LONGER SAFE.
>>>
>>>     And don't send Goog yer fingerprints either, then
>>>     the hacks/Vlad will have THOSE too. Biometrics
>>>     are only as secure as the database holding them
>>>     and these days, well ......
>>>
>>>     When's the last time you actually WENT to your
>>>     bank ? Does anyone there remember your face ?
>>>
>>
>> You’re not wrong to be skeptical — the “trust the cloud” model has always
>> relied on the hope that massive databases will stay sealed, and that’s 
>> been
>> proven false again and again. Centralized storage of credentials, 
>> biometrics,
>> and personal data is a goldmine for attackers — and the bigger the 
>> company,
>> the juicier the target.
>>
>> This isn’t even a “hack Google” event so much as an ecosystem failure. 
>> The
>> breach likely involved credential dumps from dozens of compromised 
>> sites that
>> people reused passwords on, which then get lumped together into these 
>> monster
>> datasets. It’s a reminder that *security by scale* isn’t security at 
>> all — it’s
>> just a bigger mess when it fails.
>>
>> And yes, biometrics are absolutely not magic. Once your fingerprint or 
>> face
>> data leaks, you can’t change it like a password. Combine that with how 
>> rarely
>> people visit a physical branch anymore, and you’ve got a system that’s
>> convenient but completely impersonal — and vulnerable the second the 
>> digital
>> façade cracks.
>>
>> The moral: use unique passwords, MFA, and assume every large provider 
>> is a
>> breach waiting to happen. The business model’s not broken because of 
>> bad tech
>> — it’s broken because convenience keeps winning over caution.
>>

> Jonathan Sylvester used his middle name with the number 1 appended every 
> time he set his password during 2004.

   Who the hell is Jonathan Sylvester ?

   By even recent reports, still the #1 popular password
   is "password"  :-)

   Complexity rules oft require "Password-1" as the alt.

   Most sane people will keep cross-account passwords
   'similar' enough so they can remember, or at least
   guess quick, but exactly the same PW for everything
   IS a terrible idea.

   Joe Average is unlikely to get major individual
   hack attention - one fail and they'll move on to
   the next victim. Bigger biz/govt accounts though ...

   Back when I was setting up servers, I'd always set
   the standard services like SSH, FTP, VNC and such
   to a non-standard port value. Sometimes you could
   actually catch the hacks in progress ... they'd
   scan the standards and then move on - why waste
   the time looking at, analyzing, everything ?
   Plenty of fish in the sea.

   As for e-mail and a few basics, you MIGHT look into
   some of the smaller-but-good providers instead of
   something in close orbit of Goog and big buddies.
   Goog is the Big Giant Target the evil boyz just
   can't ignore, the mother-load if they score.

   Oh, do not adopt the "Well, stupid people deserve
   to get burned !" mindset. There are mass MASS
   quantities of stupid people and if they go down
   they'll drag YOU down with them.

[toc] | [prev] | [standalone]


Back to top | Article view | alt.security


csiph-web