• If you haven't done so already, please add a location to your profile. This helps when people are trying to assist you, suggest resources, etc. Thanks (Click the "X" to the top right of this message to disable it)

Massive Password Leak

murathan

Was a Bassoonist
Joined
Mar 27, 2024
Messages
646
Reaction score
1,190
Location
Republic of Turkey
According to some news, 16 billion login and passwords are breached and leaked to dark web. You may consider changing your passwords. It seems important.

 
Now, I could be wrong, but I have to call BS on this for one simple reason... in all (without exception) password hacks that have actually happened, the people that had the hack happen to them reported it and warned their customers. On this report, it's a nice little mix of some good and a lot of bad or missing info with nothing specific at all. Having been in the computer industry for near 50 years, one tends to note small things like this.

Who was targeted? What companies were hacked? When was this first noted? Those questions are always part of any valid report... unless it's not real.

Uhhh... no, sorry, complete BS. I'll not change any of my 64-digit alphanumeric with special character passwords... I just changed them all less than a couple months ago already... lol

I would not be surprised if someone from this company called in saying they were NDTV and wanted to get in to my computer to protect me... LOL

Finally, I just did one google search on NDTV, and it was all downhill and started with this:

Don't be fooled people, this never happened.

Murathan, though, gets a good pat on the back for posting, because had it indeed been real there would have been some warnings. :)
 
For a short time, I was working with Homeland Security. Inside they had a division where security was super important. So important that they had paid this man $50,000 a year to build a random password generator. I come in, train my system to the lead group and suddenly this man has no job, and they junked the password generator app.... lol

I saw that the people were using it (they were obliged to, no choice), but the passwords were random, long and complex and they recalled it by writing the password on their arm, palm or paper... I thought, well, that is stupid!

My system is basically this, use it if you wish:

- every person has a talent, math, colours, music, etc... mine is languages, so that is what I used.
- the goal of a good password is a series of letters/numbers/symbols that does not exist in ANY dictionary on earth in any language
- depending on the security requirement, 8 characters is good, more is better. Mine are typically well over 64 digits long on sites like banking/investing, less so on other sites like here and different on every website
- You create an algorithm, this NEVER changes and exists ONLY IN YOUR HEAD, nowhere else.
- An example of a SIMPLE algorithm is...
-- use a simple word, you can even write this word on a stickie and place it on your monitor
-- apply your algorithm to that word, and that becomes your password.

Let me give you an example, this is not one that I use but used to in the past.

- choose an easy word that you document, let me randomly choose the word "god"
- translate that to a different language, I'd choose for my example Czech, so "god" becomes "pambicek"
- write the word backwards, at the 2nd spot insert a "!", in the 4th spot insert a "&" in the end add a "2".
- the above remains IDENTICAL in all future passwords using other easy simple words.
- the password now becomes "k!ec&ibmap2"

- With a little practice you can easily do this in your head with any password, and you won't ever forget it because you can choose easy words. It also covers the aspect of complexity and does not exist in any dictionary in the world.

- It makes changing passwords easy, just choose another word and apply your same algorithm again.

- Use your talent, change your passwords 2-4 times a year and enjoy security... don't reuse old passwords.

Sounds complex, but it takes longer to explain than do and isn't all that hard. At one point I had 16 different algorithms based on different levels of security required.

Create your own and enjoy. :)
 
Last edited:
Obligatory xkcd comic:
True! :D :D

I talked to a forensic ethical hacker and he told me this:
For my level 16 passwords, it would take his Cray super computer 11 months at 100% CPU time run 24/7 and exclusively for me to crack my passwords, and during that time, I will have changed it 5 times, each time requiring the system to restart the process from scratch... so basically ZERO chance of me ever being breached... lol

The big issue will always be outside my control... companies that get breached and leak my secure password and abused. So, even with all my efforts to create a good password, its only as good as the site I give it to... that's the sad part... lol
 
Back
Top