• Giant GMail Hack FINALLY Revealed

    From c186282@c186282@nnada.net to talk.politics.misc,alt.security,alt.politics,alt.politics.usa,alt.fan.rush-limbaugh on Monday, October 27, 2025 21:02:08
    From Newsgroup: alt.security

    https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183-MILLION-passwords-data-breach.html

    The incident occurred in April but has only just been disclosed

    Gmail users have been urged to check their accounts after it
    was revealed that more than 183 million passwords were stolen
    in a data breach.

    Australian cyber expert Troy Hunt, who revealed the incident,
    called it a 'vast corpus' of breached data, which totals
    3.5 terrabytes.

    To put that into perspective, that's the equivalent to 875
    full-length HD movies.

    According to Mr Hunt, 'all the major providers have email
    addresses in there' – so not just Gmail, but Outlook,
    Yahoo and others too.

    'They're from everywhere you could imagine, but Gmail
    always features heavily,' Hunt told the Daily Mail.

    . . .

    I've been saying ... the current online-biz model
    is NO LONGER SAFE.

    And don't send Goog yer fingerprints either, then
    the hacks/Vlad will have THOSE too. Biometrics
    are only as secure as the database holding them
    and these days, well ......

    When's the last time you actually WENT to your
    bank ? Does anyone there remember your face ?

    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From Tom Mix@tommix@dev.null to talk.politics.misc,alt.security,alt.politics,alt.politics.usa,alt.fan.rush-limbaugh on Tuesday, October 28, 2025 20:38:32
    From Newsgroup: alt.security

    On 2025-10-28, c186282 <c186282@nnada.net> wrote:
    https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183-MILLION-passwords-data-breach.html

    The incident occurred in April but has only just been disclosed

    Gmail users have been urged to check their accounts after it
    was revealed that more than 183 million passwords were stolen
    in a data breach.

    Australian cyber expert Troy Hunt, who revealed the incident,
    called it a 'vast corpus' of breached data, which totals
    3.5 terrabytes.

    To put that into perspective, that's the equivalent to 875
    full-length HD movies.

    According to Mr Hunt, 'all the major providers have email
    addresses in there' – so not just Gmail, but Outlook,
    Yahoo and others too.

    'They're from everywhere you could imagine, but Gmail
    always features heavily,' Hunt told the Daily Mail.

    . . .

    I've been saying ... the current online-biz model
    is NO LONGER SAFE.

    And don't send Goog yer fingerprints either, then
    the hacks/Vlad will have THOSE too. Biometrics
    are only as secure as the database holding them
    and these days, well ......

    When's the last time you actually WENT to your
    bank ? Does anyone there remember your face ?


    You’re not wrong to be skeptical — the “trust the cloud” model has always
    relied on the hope that massive databases will stay sealed, and that’s been proven false again and again. Centralized storage of credentials, biometrics, and personal data is a goldmine for attackers — and the bigger the company, the juicier the target.

    This isn’t even a “hack Google” event so much as an ecosystem failure. The
    breach likely involved credential dumps from dozens of compromised sites that people reused passwords on, which then get lumped together into these monster datasets. It’s a reminder that *security by scale* isn’t security at all — it’s
    just a bigger mess when it fails.

    And yes, biometrics are absolutely not magic. Once your fingerprint or face data leaks, you can’t change it like a password. Combine that with how rarely
    people visit a physical branch anymore, and you’ve got a system that’s convenient but completely impersonal — and vulnerable the second the digital façade cracks.

    The moral: use unique passwords, MFA, and assume every large provider is a breach waiting to happen. The business model’s not broken because of bad tech
    — it’s broken because convenience keeps winning over caution.
    --
    Tom Mix
    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From The World of Izz@jfwalby@gmaill.com to talk.politics.misc,alt.security,alt.politics,alt.politics.usa,alt.fan.rush-limbaugh on Tuesday, October 28, 2025 17:25:21
    From Newsgroup: alt.security

    Tom Mix wrote:
    On 2025-10-28, c186282 <c186282@nnada.net> wrote:
    https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183-MILLION-passwords-data-breach.html

    The incident occurred in April but has only just been disclosed

    Gmail users have been urged to check their accounts after it
    was revealed that more than 183 million passwords were stolen
    in a data breach.

    Australian cyber expert Troy Hunt, who revealed the incident,
    called it a 'vast corpus' of breached data, which totals
    3.5 terrabytes.

    To put that into perspective, that's the equivalent to 875
    full-length HD movies.

    According to Mr Hunt, 'all the major providers have email
    addresses in there' – so not just Gmail, but Outlook,
    Yahoo and others too.

    'They're from everywhere you could imagine, but Gmail
    always features heavily,' Hunt told the Daily Mail.

    . . .

    I've been saying ... the current online-biz model
    is NO LONGER SAFE.

    And don't send Goog yer fingerprints either, then
    the hacks/Vlad will have THOSE too. Biometrics
    are only as secure as the database holding them
    and these days, well ......

    When's the last time you actually WENT to your
    bank ? Does anyone there remember your face ?


    You’re not wrong to be skeptical — the “trust the cloud” model has always
    relied on the hope that massive databases will stay sealed, and that’s been proven false again and again. Centralized storage of credentials, biometrics, and personal data is a goldmine for attackers — and the bigger the company, the juicier the target.

    This isn’t even a “hack Google” event so much as an ecosystem failure. The
    breach likely involved credential dumps from dozens of compromised sites that people reused passwords on, which then get lumped together into these monster datasets. It’s a reminder that *security by scale* isn’t security at all — it’s
    just a bigger mess when it fails.

    And yes, biometrics are absolutely not magic. Once your fingerprint or face data leaks, you can’t change it like a password. Combine that with how rarely
    people visit a physical branch anymore, and you’ve got a system that’s convenient but completely impersonal — and vulnerable the second the digital
    façade cracks.

    The moral: use unique passwords, MFA, and assume every large provider is a breach waiting to happen. The business model’s not broken because of bad tech
    — it’s broken because convenience keeps winning over caution.

    Jonathan Sylvester used his middle name with the number 1 appended every
    time he set his password during 2004.
    --
    collaborate !believe protect !hunt
    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From c186282@c186282@nnada.net to talk.politics.misc,alt.security,alt.politics,alt.politics.usa,alt.fan.rush-limbaugh on Tuesday, October 28, 2025 21:41:02
    From Newsgroup: alt.security

    On 10/28/25 18:25, The World of Izz wrote:
    Tom Mix wrote:
    On 2025-10-28, c186282 <c186282@nnada.net> wrote:
    https://www.dailymail.co.uk/sciencetech/article-15230351/Gmail-183-
    MILLION-passwords-data-breach.html

    The incident occurred in April but has only just been disclosed

    Gmail users have been urged to check their accounts after it
    was revealed that more than 183 million passwords were stolen
    in a data breach.

    Australian cyber expert Troy Hunt, who revealed the incident,
    called it a 'vast corpus' of breached data, which totals
    3.5 terrabytes.

    To put that into perspective, that's the equivalent to 875
    full-length HD movies.

    According to Mr Hunt, 'all the major providers have email
    addresses in there' – so not just Gmail, but Outlook,
    Yahoo and others too.

    'They're from everywhere you could imagine, but Gmail
    always features heavily,' Hunt told the Daily Mail.

    . . .

        I've been saying ... the current online-biz model
        is NO LONGER SAFE.

        And don't send Goog yer fingerprints either, then
        the hacks/Vlad will have THOSE too. Biometrics
        are only as secure as the database holding them
        and these days, well ......

        When's the last time you actually WENT to your
        bank ? Does anyone there remember your face ?


    You’re not wrong to be skeptical — the “trust the cloud” model has always
    relied on the hope that massive databases will stay sealed, and that’s
    been
    proven false again and again. Centralized storage of credentials,
    biometrics,
    and personal data is a goldmine for attackers — and the bigger the
    company,
    the juicier the target.

    This isn’t even a “hack Google” event so much as an ecosystem failure.
    The
    breach likely involved credential dumps from dozens of compromised
    sites that
    people reused passwords on, which then get lumped together into these
    monster
    datasets. It’s a reminder that *security by scale* isn’t security at
    all — it’s
    just a bigger mess when it fails.

    And yes, biometrics are absolutely not magic. Once your fingerprint or
    face
    data leaks, you can’t change it like a password. Combine that with how
    rarely
    people visit a physical branch anymore, and you’ve got a system that’s >> convenient but completely impersonal — and vulnerable the second the
    digital
    façade cracks.

    The moral: use unique passwords, MFA, and assume every large provider
    is a
    breach waiting to happen. The business model’s not broken because of
    bad tech
    — it’s broken because convenience keeps winning over caution.


    Jonathan Sylvester used his middle name with the number 1 appended every time he set his password during 2004.

    Who the hell is Jonathan Sylvester ?

    By even recent reports, still the #1 popular password
    is "password" :-)

    Complexity rules oft require "Password-1" as the alt.

    Most sane people will keep cross-account passwords
    'similar' enough so they can remember, or at least
    guess quick, but exactly the same PW for everything
    IS a terrible idea.

    Joe Average is unlikely to get major individual
    hack attention - one fail and they'll move on to
    the next victim. Bigger biz/govt accounts though ...

    Back when I was setting up servers, I'd always set
    the standard services like SSH, FTP, VNC and such
    to a non-standard port value. Sometimes you could
    actually catch the hacks in progress ... they'd
    scan the standards and then move on - why waste
    the time looking at, analyzing, everything ?
    Plenty of fish in the sea.

    As for e-mail and a few basics, you MIGHT look into
    some of the smaller-but-good providers instead of
    something in close orbit of Goog and big buddies.
    Goog is the Big Giant Target the evil boyz just
    can't ignore, the mother-load if they score.

    Oh, do not adopt the "Well, stupid people deserve
    to get burned !" mindset. There are mass MASS
    quantities of stupid people and if they go down
    they'll drag YOU down with them.

    --- Synchronet 3.21e-Win32 NewsLink 1.2