Yahoo confirms that all accounts were compromised

As long as you’re not still using that password (I hope not), you’re mostly safe.

I am pretty sure my password is different than the last one I used.

But since many of those passes are either very old accounts, troll accounts, or forgotten ones, wouldnt that skew the tables somewhat? Considering that most folks didnt seriously use yahoo, would that matter? Or is it more of a psychological thing to figure out how people think when they create passes?

i know alot of people who still use yahoo seriously.

even if 75% of accounts were just troll accounts with fake passwords that is still a whole 750,000 accounts with more modern passwords.

The whole point of using actual passwords is that they are actual passwords that most people use plus the passwords follow patterns ALOT of people use. Like having the first letter be capital, exclamation point at the end, series of numbers near the end, leet speek to replace letters, etc. You can at the very least use the passwords to model a password generator that is very close to the passwords people actually use

2 Likes

I use two factor with my yahoo and other accounts, I expect all the things to be pwned- and even two factor via SMS is not that effective. Google is going to offer hardware for higher target people for their google accounts.

1 Like

Hardware 2fa devices? So just a software 2fa that’s been put on an embedded device?

2 Likes

For the plebes-

For the nobles-

Also known as Plain old RFC6238

https://tools.ietf.org/html/rfc6238

1 Like

Not saying google invented it, saying they will start using it.

I like this concept (Sound-Proof), not because it’s uber secure, but convenient- and that was their selling point, that more people would adopt optional 2fa if its more convenient to use.
https://www.usenix.org/node/190981

That is one really bizarre authentication mechanism. Why use the ambient sound when they are already close together? Why not play a encoded signal?

Just odd on very many levels.

Also funny:
image

Thats a good question… maybe because of variance between phone manufacturer speakers especially in the inaudible ranges. I believe they avoided ambient sound inaudible frequencies as part of the sound sample for quality reasons.