SearchVoatBot

This submission was linked from this v/techhell comment by @flyingcuttlefish .

Posted automatically (#20219) by the SearchVoat.co Cross-Link Bot. You can suppress these notifications by appending a forward-slash(/) to your Voat link. More information here .

cantfindmenow

Theres these too. Not sure if from same dump. Clinton emails and passwords: https://8ch.net/qresearch/res/4857412.html#4857870 Many CNN email accounts and passwords: https://pastebin.com/C1QkZEWe

followthemoney

It is from the Collection #1 release.

IShallNotFear

That NObama2008 one is funny. I guess someone was still bitter about the campaign loss.

Vindicator

Thanks for posting this, @followthemoney . Can you please move the source link from the Comments (where it will be buried) to the body of your post? I'll give you the 24 Hour Grace flair, so you can edit per Rule 2.

think-

@Vindicator , OP has edited the post. :-)

EricKaliberhall

Tack think-, I'll remove the flair.

@Vindicator

think-

Welcome, Eric. Apologies, I should have pinged you as well.

EricKaliberhall

No worries... I see all my friend. :)

think-

;-) :-)

shewhomustbeobeyed

https://www.zerohedge.com/news/2019-01-17/largest-cache-hacked-data-history-discovered-over-770-million-email-addresses-21

New breach: The "Collection #1" credential stuffing list began broadly circulating last week and contains 772,904,991 unique email addresses with plain text passwords (now in Pwned Passwords). 82% of addresses were already in @haveibeenpwned . Read more: https://t (.)co/BAa3rbgZo4

https://archive.fo/IOiF9


havebeenpwned - https://web.archive.org/web/20190121002139/https://haveibeenpwned.com/

troyhunt - https://archive.is/vobkL

wordpress - https://archive.is/RRLeW

think-

Hi @followthemoney , thanks for the repost! :-) Now I better understand what the post is about. :-)

Ahem - you would still need to put one link in, otherwise the mods will flair the post.... ;-)

Cheers.

Imnotshocked

So what does it mean if your on that list? They have all My emails?

followthemoney

They have your password and email address and it is available to anyone who can download the torrent and run scripts on the binary files.

Imnotshocked

Thanks, I changed the password.

followthemoney

It helps to use different passwords, don't use accounts with your name on it, and use a variety of plugins like decentraleyes and ublock origin.

Imnotshocked

What do you mean everyone’s browser history? How do they get that from your email address?

followthemoney

If someone logs into your chrome, they see can your history across all devices.

It is simple to use a tool to attempt to login from rotating IP addresses.

It is only a matter of time before everyone is exposed.

think-

They can read your emails if your email address is among those they hacked. You can find out by using this site:

https://haveibeenpwned.com/

and type in your email address(es) you used in the past years. But please DONT use the site to check your passwords (!!!)

If the site turns red, it means the email address in question got hacked at some point. That means you should change your password for that email address ASAP.

Imnotshocked

Yes it was on the list . My other family members were not on it . Wierd

think-

....maybe they have more complicated passwords that were more difficult to hack?

Anyway, you might want to change your password now.

Imnotshocked

Yes I changed it but it was a really strong password

think-

K

Traveler

Oh stonetear

flyingcuttlefish

x-post: Biggest Hack - Over 770 Million Email Addresses, 21 Million Passwords https://voat.co/v/techhell/2979152

Adminstrater

Is this from "The 773 Million Record "Collection #1" Data Breach"?

You can check your email addresses here: https://haveibeenpwned.com/

Edit: There is a place to check to see if your password has been compromised, but I DO NOT recommend using it, as typing any of your passwords into a strange website is always, Always, ALWAYS bad news.

think-

I DO NOT recommend using it, as typing any of your passwords into a strange website is always, Always, ALWAYS a bad idea.

Indeed. Checking an email address on the site is fine, but I hope nobody will type in passwords.

Adminstrater

The only passwords I might suggest you could perhaps try, is your OLD passwords. The one you use for no-need-secure accounts, and the oldest passwords you had used in the past, AND NO LONGER USE . I had a 8 digit (same as my luggage), all number password I used for some simple coding forums when I was learning and just asking questions under an alias. That password is no longer being used by me because of its age, but also because of how insecure it is, and now I have verified that it was cracked in the QuinStreet breach:

QuinStreet: In approximately late 2015, the maker of "performance marketing products" QuinStreet had a number of their online assets compromised. The attack impacted 28 separate sites, predominantly technology forums such as flashkit.com, codeguru.com and webdeveloper.com (view a full list of sites) . QuinStreet advised that impacted users have been notified and passwords reset. The data contained details on over 4.9 million people and included email addresses, dates of birth and salted MD5 hashes.

Compromised data: Dates of birth, Email addresses, IP addresses, Passwords, Usernames, Website activity

followthemoney

You can check to see which breaches you are on, but I think you have to go through a few hoops to get the passwords.

Adminstrater

I think the hoops would be to find and download the 87GB folder.

BlowjaySimpson

And salt the hashes in most cases, before you can crack it to a usable password.

Adminstrater

That is true, because the hacks would require having to acquire the hashing and salting algorithm for any passwords that were used to hash the passwords, since majority of these websites that were hacked were not storing passwords in raw format.

fuckmyreddit

I dont know how to help but my comment might bump this up higher.

Joe10jo

Had no idea that commenting helps to bump. Bumping.

think-

Had no idea that commenting helps to bump. Bumping.

LOL. Yes, it does. ;-)