Page 1 of 1

Posted: Thu Jan 17, 2019 1:46 pm
by peet
https://www.troyhunt.com/the-773-millio ... ata-reach/

No I do not have to tell you guys again to change your passwords...

Posted: Thu Jan 17, 2019 6:10 pm
by Broodwich
2fa ftw

Posted: Thu Jan 17, 2019 7:33 pm
by pkk
Broodwich wrote:QUOTE (Broodwich @ Jan 17 2019, 07:10 PM) 2fa ftw
https://github.com/kgretzky/evilginx2 :lol:
https://vimeo.com/281220095

Posted: Thu Jan 17, 2019 11:25 pm
by Broodwich
You still have to click on a bad link to get hijacked... which is how every other piece of malware/phishing works. I was referring to an attacker being able to get into your accounts from this email/password dump

Interesting video though

Posted: Fri Jan 18, 2019 7:40 am
by peet
Once a year the great people of the Chaos Computer Club have a 4 day conference, which gives me a good sense about the current of (in)secure things. It gives me great pleasure at least one European country actually cares about privacy.

I can recommend viewing some lectures, a lot are in English or translated to English.

Posted: Fri Jan 25, 2019 6:53 pm
by pkk
Much nicer than SpyCloud and HaveIbeenpwned, because it provides some more information:
https://sec.hpi.de/ilc/?lang=en

Posted: Fri Jan 25, 2019 6:59 pm
by Broodwich
Nifty

Posted: Sat Jan 26, 2019 12:45 am
by Terran
pkk wrote:QUOTE (pkk @ Jan 25 2019, 01:53 PM) Much nicer than SpyCloud and HaveIbeenpwned, because it provides some more information:
https://sec.hpi.de/ilc/?lang=en
how cool would it be if that site was actually ran by criminals looking for email addresses to target?

Posted: Thu Jan 31, 2019 2:35 pm
by peet
https://www.wired.com/story/collection- ... -billions/

It seems there is also new account data in this new batch, added to the old known data.