I rarely (read never) post on forums, but I think this topic needs more attention.
This to all the lovely players here, even to those who give me/us extra love like Oran.
This is not about terms in the title as you can search for it .... also these are my observations over the years YMMV
2FA
(Torn):
Prerequisites:
You play Torn -> I assume you have a mobile phone -> setup MFA. Yes, you can feel pain. Get used to it or remove it:( .
(whatever app you care about):
Based on what is important to you, there is one thing that should have any possible security option enabled.
Your primary email, which you use for banks/government/.... and in most cases is one of the recovery options for other accounts.
If abused, you may lose a lot as a big part of your life can be "recovered" and misused.
Password managers(PM):
Depending on how often you work with a PC and how many different logins/accounts you have -> Try to think about using it!
Which to choose:
There is a big variety and the two most factors are usability/functions(Win or Mac, mobile yes/no, backup, MFA!) and "how secure is it".
To my surprise, many people around from Fortune 500 IT companies use BitWarden (use it as you want, I use something else).
Things to consider when using PM:
You have email, bank account, and Facebook (and you use Facebook for all other Internet "life").
Choose 3 different passwords, set up Authenticator on your mobile(and set up backups!) , 2FA all of the accounts and that's it.
Please don't use only the password.
Use-case 2 (I care about security and I spend a lot of time online using many sites):
MFA for all key accounts.
Primary email for banking and private or sensitive stuff.
Secondary email for all the registrations (Discord, porn sites, shopping, ....)
PM of your choice(MFA, backups, recovery in place!).
Use-case 3 (I want to be as safe as possible):
You know much more, I don't have to tell you.
You can stop reading here.
-----------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------
Learning from past experience (no succ. account compromise ever):
https://haveibeenpwned.com/
[background color=var(--bbc-body-bg-color)]Breaches you were pwned in[/background]
Collection #1 (unverified): In January 2019, a large collection of credential stuffing lists (combinations of email addresses and passwords used to hijack accounts on other services) was discovered being distributed on a popular hacking forum. The data contained almost 2.7 billion records including 773 million unique email addresses alongside passwords those addresses had used on other breached services. Full details on the incident and how to search the breached passwords are provided in the blog post The 773 Million Record "Collection #1" Data Breach.
Compromised data: Email addresses, Passwords
Data Enrichment Exposure From PDL Customer: In October 2019, security researchers Vinny Troia and Bob Diachenko identified an unprotected Elasticsearch server holding 1.2 billion records of personal data. The exposed data included an index indicating it was sourced from data enrichment company People Data Labs (PDL) and contained 622 million unique email addresses. The server was not owned by PDL and it's believed a customer failed to properly secure the database. Exposed information included email addresses, phone numbers, social media profiles and job history data.
Compromised data: Email addresses, Employers, Geographic locations, Job titles, Names, Phone numbers, Social media profil
Exploit.In (unverified): In late 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Exploit.In". The list contained 593 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned.
Compromised data: Email addresses, Passwords
Gravatar: In October 2020, a security researcher published a technique for scraping large volumes of data from Gravatar, the service for providing globally unique avatars . 167 million names, usernames and MD5 hashes of email addresses used to reference users' avatars were subsequently scraped and distributed within the hacking community. 114 million of the MD5 hashes were cracked and distributed alongside the source hash, thus disclosing the original email address and accompanying data. Following the impacted email addresses being searchable in HIBP, Gravatar release an FAQ detailing the incident.
Compromised data: Email addresses, Names, Usernames
Heroes of Newerth: In December 2012, the multiplayer online battle arena game known as Heroes of Newerth was hacked and over 8 million accounts extracted from the system. The compromised data included usernames, email addresses and passwords.
Compromised data: Email addresses, Passwords, Usernames
LinkedIn: In May 2016, LinkedIn had 164 million email addresses and passwords exposed. Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were stored as SHA1 hashes without salt, the vast majority of which were quickly cracked in the days following the release of the data.
Compromised data: Email addresses, Passwords
LinkedIn Scraped Data: During the first half of 2021, LinkedIn was targeted by attackers who scraped data from hundreds of millions of public profiles and later sold them online. Whilst the scraping did not constitute a data breach nor did it access any personal data not intended to be publicly accessible, the data was still monetised and later broadly circulated in hacking circles. The scraped data contains approximately 400M records with 125M unique email addresses, as well as names, geographic locations, genders and job titles. LinkedIn specifically addresses the incident in their post on An update on report of scraped data.
Compromised data: Education levels, Email addresses, Genders, Geographic locations, Job titles, Names, Social media profiles
You've Been Scraped: In October and November 2018, security researcher Bob Diachenko identified several unprotected MongoDB instances believed to be hosted by a data aggregator. Containing a total of over 66M records, the owner of the data couldn't be identified but it is believed to have been scraped from LinkedIn hence the title "You've Been Scraped". The exposed records included names, both work and personal email addresses, job titles and links to the individuals' LinkedIn profiles.
Compromised data: Email addresses, Employers, Geographic locations, Job titles, Names, Social media profiles
This to all the lovely players here, even to those who give me/us extra love like Oran.
This is not about terms in the title as you can search for it .... also these are my observations over the years YMMV
2FA
(Torn):
Prerequisites:
You play Torn -> I assume you have a mobile phone -> setup MFA. Yes, you can feel pain. Get used to it or remove it:( .
(whatever app you care about):
Based on what is important to you, there is one thing that should have any possible security option enabled.
Your primary email, which you use for banks/government/.... and in most cases is one of the recovery options for other accounts.
If abused, you may lose a lot as a big part of your life can be "recovered" and misused.
Password managers(PM):
Depending on how often you work with a PC and how many different logins/accounts you have -> Try to think about using it!
Which to choose:
There is a big variety and the two most factors are usability/functions(Win or Mac, mobile yes/no, backup, MFA!) and "how secure is it".
To my surprise, many people around from Fortune 500 IT companies use BitWarden (use it as you want, I use something else).
Things to consider when using PM:
- On 1 device or portable
- Fits your MFA
- Customization without external "unverified" sources
- Database backup configuration (backup to external physical storage at least once per year!)
- Check recent or recurring problems related to PM (Try something simple like "CVE LastPass GitHub") or just check the news :)
- If you fail to open the PM database, what are your recovery options
- PM can be used by a trusted person in case of emergency (you are in hospital and your wife needs to log in somewhere)
You have email, bank account, and Facebook (and you use Facebook for all other Internet "life").
Choose 3 different passwords, set up Authenticator on your mobile(and set up backups!) , 2FA all of the accounts and that's it.
Please don't use only the password.
Use-case 2 (I care about security and I spend a lot of time online using many sites):
MFA for all key accounts.
Primary email for banking and private or sensitive stuff.
Secondary email for all the registrations (Discord, porn sites, shopping, ....)
PM of your choice(MFA, backups, recovery in place!).
Use-case 3 (I want to be as safe as possible):
You know much more, I don't have to tell you.
You can stop reading here.
-----------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------
Learning from past experience (no succ. account compromise ever):
https://haveibeenpwned.com/
[background color=var(--bbc-body-bg-color)]Breaches you were pwned in[/background]
Collection #1 (unverified): In January 2019, a large collection of credential stuffing lists (combinations of email addresses and passwords used to hijack accounts on other services) was discovered being distributed on a popular hacking forum. The data contained almost 2.7 billion records including 773 million unique email addresses alongside passwords those addresses had used on other breached services. Full details on the incident and how to search the breached passwords are provided in the blog post The 773 Million Record "Collection #1" Data Breach.
Compromised data: Email addresses, Passwords
Data Enrichment Exposure From PDL Customer: In October 2019, security researchers Vinny Troia and Bob Diachenko identified an unprotected Elasticsearch server holding 1.2 billion records of personal data. The exposed data included an index indicating it was sourced from data enrichment company People Data Labs (PDL) and contained 622 million unique email addresses. The server was not owned by PDL and it's believed a customer failed to properly secure the database. Exposed information included email addresses, phone numbers, social media profiles and job history data.
Compromised data: Email addresses, Employers, Geographic locations, Job titles, Names, Phone numbers, Social media profil
Exploit.In (unverified): In late 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Exploit.In". The list contained 593 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned.
Compromised data: Email addresses, Passwords
Gravatar: In October 2020, a security researcher published a technique for scraping large volumes of data from Gravatar, the service for providing globally unique avatars . 167 million names, usernames and MD5 hashes of email addresses used to reference users' avatars were subsequently scraped and distributed within the hacking community. 114 million of the MD5 hashes were cracked and distributed alongside the source hash, thus disclosing the original email address and accompanying data. Following the impacted email addresses being searchable in HIBP, Gravatar release an FAQ detailing the incident.
Compromised data: Email addresses, Names, Usernames
Heroes of Newerth: In December 2012, the multiplayer online battle arena game known as Heroes of Newerth was hacked and over 8 million accounts extracted from the system. The compromised data included usernames, email addresses and passwords.
Compromised data: Email addresses, Passwords, Usernames
LinkedIn: In May 2016, LinkedIn had 164 million email addresses and passwords exposed. Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were stored as SHA1 hashes without salt, the vast majority of which were quickly cracked in the days following the release of the data.
Compromised data: Email addresses, Passwords
LinkedIn Scraped Data: During the first half of 2021, LinkedIn was targeted by attackers who scraped data from hundreds of millions of public profiles and later sold them online. Whilst the scraping did not constitute a data breach nor did it access any personal data not intended to be publicly accessible, the data was still monetised and later broadly circulated in hacking circles. The scraped data contains approximately 400M records with 125M unique email addresses, as well as names, geographic locations, genders and job titles. LinkedIn specifically addresses the incident in their post on An update on report of scraped data.
Compromised data: Education levels, Email addresses, Genders, Geographic locations, Job titles, Names, Social media profiles
You've Been Scraped: In October and November 2018, security researcher Bob Diachenko identified several unprotected MongoDB instances believed to be hosted by a data aggregator. Containing a total of over 66M records, the owner of the data couldn't be identified but it is believed to have been scraped from LinkedIn hence the title "You've Been Scraped". The exposed records included names, both work and personal email addresses, job titles and links to the individuals' LinkedIn profiles.
Compromised data: Email addresses, Employers, Geographic locations, Job titles, Names, Social media profiles