23 points

Woof. This is why it’s critically important to use a password manager. We simply have too many accounts to remember unique passwords, and repeatedly we see some of those accounts will get breached and your details stolen.

permalink
report
reply
16 points
*

This is why it’s critically important to use a password manager.

Except for people who used 1Password, DashLane, LastPass, Enpass, Keeper, and Keepass2Android.

permalink
report
parent
reply
13 points

Yep, bitwarden for the win

permalink
report
parent
reply
1 point

Self-hosted for the double win.

permalink
report
parent
reply
3 points

When and how has keepass2aandroid been compromised?

permalink
report
parent
reply
1 point

Autospill affects Android password programs including keepass2android. Not a flaw in Keepass (which I use) but in Android.

permalink
report
parent
reply
1 point

Why??

permalink
report
parent
reply
2 points

They’ve been hacked. So therefore you’ve been extremely fucking hacked.

permalink
report
parent
reply
21 points
*

Anyone have a link to the actual list? [Or, more specifically, has haveibeenpwned incorporated it? I can’t find anything on their site stating so.]

permalink
report
reply
3 points

The article says their tool “will” include the new ones, so I plan to check it and haveibeenpwned in a couple days.

permalink
report
parent
reply
2 points

Thanks, mate! I’m sure I can find the list on the dn somewhere, but I don’t actually want/need the list itself.

permalink
report
parent
reply
2 points

Same and I’m not sure I want my browser history to have that I went looking for it lol

permalink
report
parent
reply
2 points

https://haveibeenpwned.com/ is another option that has the largest data base of passwords, phone numbers and e-mail

permalink
report
parent
reply
3 points

But did they incorporate this 2024 list, yet?

permalink
report
parent
reply
2 points

Appreciate it, cheers!

permalink
report
parent
reply
4 points

So, only passwords, right? Not associated with usernames?

permalink
report
reply
11 points
*

I would assume that because the original rockyou list was always just used for dictionary brute force attacks, so no associated usernames.

permalink
report
parent
reply
11 points

Correct. This is a brute force dictionary. It’s a very powerful tool, but it’s applications are severely limited. Any well designed system has protection from brute force attacks. It’s mostly useful for stuff like cracking encrypted databases, which would be a situation where the target is entirely under your control. You can’t just break into someone’s Gmail with it.

permalink
report
parent
reply
2 points
*

How would you even crack an encrypted database? I guess the hacker somehow stole it from the server and has it in their dump of other databases they’re trying to crack? I don’t do hacking, I’m just curious with how it works.

permalink
report
parent
reply
4 points

password123 is still my password of choice.

permalink
report
reply
3 points

Nah, I’d say the passwords from Hackers (1995) such as love, sex, secret, god are the best.

permalink
report
parent
reply

Cybersecurity

!cybersecurity@sh.itjust.works

Create post

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We’re all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your “friends” socials you’re just going to get banned so don’t do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

Community stats

  • 1.6K

    Monthly active users

  • 954

    Posts

  • 2K

    Comments