The 773 Million Record Collection #1 Data Breach

Page 2 of 5 FirstFirst 1234 ... LastLast

  1. Posts : 1,560
    Windows 10 Home 20H2 64-bit
       #10

    Right, so as an example; Let say tenforums is breached, then my mail address and password for tenforums is leaked. That's what this breach is all about? So Collection #1 then may have that mail address and password for tenforums on that list, correct? Sorry for all the questions, I'm just trying to make sense of this before puting on a tin foil hat.
      My Computer


  2. Posts : 27,181
    Win11 Pro, Win10 Pro N, Win10 Home, Windows 8.1 Pro, Ubuntu
       #11

    Faith said:
    Right, so as an example; Let say tenforums is breached, then my mail address and password for tenforums is leaked. That's what this breach is all about? So Collection #1 then may have that mail address and password for tenforums on that list, correct? Sorry for all the questions, I'm just trying to make sense of this before puting on a tin foil hat.
    Correct.
    Then both might get tested with Banks/Facebook/Twitter/your actual Email account and so on.
    If one can then get into those accounts they can steal not only information, but steal your Identity!
      My Computers


  3. Posts : 1,560
    Windows 10 Home 20H2 64-bit
       #12

    Thanks the answers, and for putting my mind at ease Cliff. If the main password from Google or Microsoft ever get leaked, hopefully they will inform us about it. I also use two-ways security + code-chip for my most important stuff.
      My Computer


  4. Posts : 10,740
    Windows 11 Workstation x64
       #13

    Unique passwords are good, but for any important site such as Paypal, Amazon, Email Provider etc. you should always enable Two-factor authentication if it's available, your email provider is the most important as if they can get in to that they can reset the password to all the sites you use that email for.
      My Computers


  5. Posts : 27,181
    Win11 Pro, Win10 Pro N, Win10 Home, Windows 8.1 Pro, Ubuntu
       #14

    Another thing you might want to think about is get a few Alias's(throwaway accounts) and use those for sites, and reserve your actual Email accounts for only important things,

    For Hotmail & Outlook:
    Add or remove an email alias in Outlook.com - Outlook

    For Gmail:
    https://support.google.com/mail/answer/22370?hl=en
      My Computers


  6. Posts : 27,181
    Win11 Pro, Win10 Pro N, Win10 Home, Windows 8.1 Pro, Ubuntu
       #15

    I just wrote this under Troy's video I posted above:

    Microsoft should build in a Password Manager connected to HIBP & HIBP/Password, into Windows or Edge but it seems only bling bling and pretty icons, and taco hats & ninja cats are most important to them
      My Computers


  7. Posts : 750
    Windows 10 Pro 64-bits
       #16

    Cliff S said:
    If your Email address pops up on haveibeenpwned there is a separate site to check passwords separately Have I Been Pwned: Pwned Passwords

    Troy Hunt: Introducing 306 Million Freely Downloadable Pwned Passwords
    Call me overly cautious, but I have some reservation about typing in my current password to a website, just for testing purposes.
      My Computer


  8. Posts : 750
    Windows 10 Pro 64-bits
       #17

    z3r010 said:
    Unique passwords are good, but for any important site such as Paypal, Amazon, Email Provider etc. you should always enable Two-factor authentication if it's available, your email provider is the most important as if they can get in to that they can reset the password to all the sites you use that email for.
    Good advise, but...

    Most of the 2FA rely on texting the PIN to a cell, that requires providing the cell number obviously. Some sites, especially the sites with their app on the cell, may use the GPS on the cell for advertisement purposes, like Facebook did. Others probably have not been caught as of yet...
      My Computer


  9. Posts : 10,740
    Windows 11 Workstation x64
       #18

    Cr00zng said:
    Good advise, but...

    Most of the 2FA rely on texting the PIN to a cell, that requires providing the cell number obviously. Some sites, especially the sites with their app on the cell, may use the GPS on the cell for advertisement purposes, like Facebook did. Others probably have not been caught as of yet...
    Most sites use a universal authenticator app such a google authenticator or Authy or hardware like a yubikey, not many use cell phone code these days.
      My Computers


  10. Posts : 27,181
    Win11 Pro, Win10 Pro N, Win10 Home, Windows 8.1 Pro, Ubuntu
       #19

    Cr00zng said:
    Call me overly cautious, but I have some reservation about typing in my current password to a website, just for testing purposes.
    When you search Pwned Passwords
    The Pwned Passwords feature searches previous data breaches for the presence of a user-provided password. The password is hashed client-side with the SHA-1 algorithm then only the first 5 characters of the hash are sent to HIBP per the Cloudflare k-anonymity implementation. HIBP never receives the original password nor enough information to discover what the original password was.
    Have I Been Pwned: Privacy
      My Computers


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 12:14.
Find Us




Windows 10 Forums