📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

711 million email addresses/passwords compromised

Options
711,477,622 email addresses/passwords have been compromised according to "Have I been pwned?"

https://www.troyhunt.com/inside-the-massive-711-million-record-onliner-spambot-dump/

Should we be worried?

Comments

  • esuhl
    esuhl Posts: 9,409 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    edited 30 August 2017 at 6:32AM
    Harrumph. My personal email address is listed.

    At first I was puzzled as I don't use this address as a login, but apparently there are both email/password logins and just email address to send spam to.
  • poppellerant
    poppellerant Posts: 1,963 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    It'd be interesting to see which password they are using - that'd tell me how recent their password is and if I needed to change it. As it happens I don't know, so I'll change my passwords anyway.

    Hurrah!
  • AndyPix
    AndyPix Posts: 4,847 Forumite
    Fifth Anniversary 1,000 Posts Name Dropper Photogenic
    This is very old news
  • RumRat
    RumRat Posts: 5,019 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    =SpanishBlue
    Should we be worried?
    No, not really, they are used mainly for spam and have been out there for some time.
    Anyway, lifes far too short.....;)
    Drinking Rum before 10am makes you
    A PIRATE
    Not an Alcoholic...!
  • S0litaire
    S0litaire Posts: 3,535 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    That's the main problem with sites like "HiBP".
    you can't tell what password is listed in the list.
    So it's hard to tell if it's from an old list (and you've since changed your password!)
    Or it's a new list (Then a new password is required!)
    Laters

    Sol

    "Have you found the secrets of the universe? Asked Zebade "I'm sure I left them here somewhere"
  • kwikbreaks
    kwikbreaks Posts: 9,187 Forumite
    Although some passwords are in plain text most are going to be hashes which shouldn't be possible to convert back to a password. If the companies were taking any care at all of user data there should be no plain text passwords but it seems that 000webhost for one did store plain text passwords. One of mine is there but is of zero consequence to me.
  • Lorian
    Lorian Posts: 6,268 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    This list is not quite what it seems.

    Of the 112 entries on it that belong in my email domains 109 are totally random made up addresses that have never existed, and the other 3 were compromised a long time ago in other events.
  • forgotmyname
    forgotmyname Posts: 32,931 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    000webhost could be the one i used and that email address comes up on the list. But i never reuse passwords and they are all unique in format.

    I have a very random way of creating passwords, whats currently on my desk or on my screen and then jumble it around with a mix of numbers etc.
    Censorship Reigns Supreme in Troll City...

This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.2K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.7K Spending & Discounts
  • 244.2K Work, Benefits & Business
  • 599.3K Mortgages, Homes & Bills
  • 177K Life & Family
  • 257.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.