We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Password breach warning on HL?

Options
24

Comments

  • Swipe
    Swipe Posts: 5,607 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    dunstonh said:
    dunroving said:
    It's a valid warning. It's not saying you've done anything wrong but that at some point, somewhere on the internet, someone has used the username/password combination as an authentication to a site, and that site leaked that authentication data to a malicious actor.

    Whilst your HL account is unlikely to be accessed, you should still change your password as it is a risk that you can mitigate easily. Use a random generator for your next password.

    Thank Chrome for the service rather than ignore it!
    The problem with completely randomly generated passwords is you have to write them down somewhere. I use passwords nobody would guess, but I have a system to remember. As per your advice, I'll change my password (again). 
    Look up bitwarden.   https://bitwarden.com/
    There are others (such as LastPass, dashlane etc).  
    This is the best advice anyone can offer you. I really don't understand anyone who doesn't use a password manager in this day and age. And write down your master password somewhere safe.

  • dunroving
    dunroving Posts: 1,903 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    Swipe said:
    dunstonh said:
    dunroving said:
    It's a valid warning. It's not saying you've done anything wrong but that at some point, somewhere on the internet, someone has used the username/password combination as an authentication to a site, and that site leaked that authentication data to a malicious actor.

    Whilst your HL account is unlikely to be accessed, you should still change your password as it is a risk that you can mitigate easily. Use a random generator for your next password.

    Thank Chrome for the service rather than ignore it!
    The problem with completely randomly generated passwords is you have to write them down somewhere. I use passwords nobody would guess, but I have a system to remember. As per your advice, I'll change my password (again). 
    Look up bitwarden.   https://bitwarden.com/
    There are others (such as LastPass, dashlane etc).  
    This is the best advice anyone can offer you. I really don't understand anyone who doesn't use a password manager in this day and age. And write down your master password somewhere safe.

    I always wonder, though - if other passwords can be somehow hacked, what's to stop the master password for a password manager being hacked in the same way? (Genuine question)
    (Nearly) dunroving
  • masonic
    masonic Posts: 27,172 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    dunroving said:
    Swipe said:
    dunstonh said:
    dunroving said:
    It's a valid warning. It's not saying you've done anything wrong but that at some point, somewhere on the internet, someone has used the username/password combination as an authentication to a site, and that site leaked that authentication data to a malicious actor.

    Whilst your HL account is unlikely to be accessed, you should still change your password as it is a risk that you can mitigate easily. Use a random generator for your next password.

    Thank Chrome for the service rather than ignore it!
    The problem with completely randomly generated passwords is you have to write them down somewhere. I use passwords nobody would guess, but I have a system to remember. As per your advice, I'll change my password (again). 
    Look up bitwarden.   https://bitwarden.com/
    There are others (such as LastPass, dashlane etc).  
    This is the best advice anyone can offer you. I really don't understand anyone who doesn't use a password manager in this day and age. And write down your master password somewhere safe.

    I always wonder, though - if other passwords can be somehow hacked, what's to stop the master password for a password manager being hacked in the same way? (Genuine question)
    It's not passwords that are hacked, it's companies storing passwords in a way that allows said company to access them. If you are the only one who knows your password, and it isn't guessable, then it won't be hacked. If you want to be really sure, don't use a service that stores anything online. Never, use a password manager with the ability to recover a lost master password.
  • ChesterDog
    ChesterDog Posts: 1,144 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    Just happened to me too.
    My passwords are all unique, not word-based and so on.
    It's looking like some sort of Chrome/HL glitch to me.
    I am one of the Dogs of the Index.
  • ChesterDog
    ChesterDog Posts: 1,144 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    ...especially as it's also warning me with my fresh password.
    I am one of the Dogs of the Index.
  • masonic
    masonic Posts: 27,172 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    Just happened to me too.
    My passwords are all unique, not word-based and so on.
    It's looking like some sort of Chrome/HL glitch to me.
    Sometimes when sites ask you to enter things like your date of birth and random digits from a password, those can be mistaken for username and password. I'd imagine a 6 digit number username and single character password would be quite likely to trigger an alert.
  • veryintrigued
    veryintrigued Posts: 3,843 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    Happened to me yesterday too.

    Logged on today and nothing.

    I've done nothing in between

  • barnstar2077
    barnstar2077 Posts: 1,648 Forumite
    Eighth Anniversary 1,000 Posts Name Dropper Photogenic
    edited 15 July 2020 at 9:03PM
    I don't trust password generators.  I write sixteen character jumbled passwords in a little book.  I write it out normally, but they are all useless unless you know that the third character is always an x regardless of what it says in the book.  It means that they are not stored electronically by me, and they are useless to anyone that might see the book (which is also hidden obviously.)

    Edit:  Also, I use one email for my banking and important stuff, and another that I use on everything else and give to people.  Plenty of people have been caught out because they use the same email / password on poorly secured sites that they do for online banking, Amazon etc.
    Think first of your goal, then make it happen!
  • ANGLICANPAT
    ANGLICANPAT Posts: 1,455 Forumite
    Part of the Furniture 1,000 Posts
    Ive changed both my security number and Password again  now  (3rd time)   and this one is an  absolutely random mixture of  caps and  lower case letters , digits, and allowed symbols  - 15 in all ,  and Im still getting the same Chrome message. Surely must be a glitch .
  • sebtomato
    sebtomato Posts: 1,119 Forumite
    Part of the Furniture 500 Posts Name Dropper Combo Breaker
    Same warning for me, on both PC and smartphone (Chrome browser on Android).
    Changed my password, and still getting the same warning, so must be a glitch. However, you would expect HL to put some banner on their website to advise people using Chrome but of course nothing.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.9K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.9K Work, Benefits & Business
  • 598.7K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.