Everybody's password stolen - almost

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

destrekor

Lifer
Nov 18, 2005
28,799
359
126
You're part of a society who calls it hacking when they find somebody still logged into Facebook, so I think you're fighting a losing battle.

According to mainstream news: "Any bad thing done to a computer system = hacking," even if you gained access by using login information that you got simply by asking someone for it.

Sometimes, I like to forget. It keeps my hopes up.
 

Jeff7

Lifer
Jan 4, 2001
41,596
19
81
Sometimes, I like to forget. It keeps my hopes up.
Yeah.
Likewise, it's often not safe for me to mingle when I'm out and about.
I learn too much about other people.



Faster than I can think, more often than not.

No idea, haven't measured WPM in forever. I've been tested before to reach 80-90+, but I can be sloppy too, especially if I'm just typing by way of a stream of consciousness moment.


I'm known for writing "novels" at work - e-mails. Though I've come to learn that "Greater than 140 words" is "holy shit, how long did it take you to type that?"
I know some people who use a computer every day, but still type like they've never seen one before. Their e-mails tend to be lacking in length, as well as information content.
(Ask a question that's looking for an explanation and the backstory surrounding a situation. Reply: "Yup, sounds good.")

- Send e-mail short enough to be read, which causes information to be lost: Didn't understand it. Deleted it.
- Short enough to be read, includes the necessary information, but the vocabulary is too lofty: Didn't understand it. Deleted it.
- Reasonable vocabulary, and long enough to convey the necessary information: tl;dr


I suppose everyone should be glad my joints are becoming saddled with RSI from years of rapidly and efficiently using a computer, and that my coordination has never been terribly good. Otherwise, I might type even faster. (I think I max out at around 60-70WPM. :\ Beyond that, my hands get out of sequence. The left and right will end up trying to type their letters in parallel. Damn FIFO input devices...)
 

silverpig

Lifer
Jul 29, 2001
27,703
12
81
According to mainstream news: "Any bad thing done to a computer system = hacking," even if you gained access by using login information that you got simply by asking someone for it.

"Hacking" = selecting the advanced install and including support for another language.
 

akugami

Diamond Member
Feb 14, 2005
6,210
2,551
136
Holy crap...my twitter and facebook passwords might be stolen...time to make an account on twitter and facebook to check...
 

ImpulsE69

Lifer
Jan 8, 2010
14,946
1,077
126
Holy crap...my twitter and facebook passwords might be stolen...time to make an account on twitter and facebook to check...

Make sure to do it from some place public. You never know what kind of hoodlums could be watching your PC just waiting..waiting..
 

l Thomas l

Senior member
Nov 29, 2005
242
0
0
I just started working for a company that uses ADP. My SSN is in their system.. They have printed it out on documents, in full. And they still use Internet Explorer too. Not too many technical people at this job. Obviously not too concerned about privacy. Is there anything I can do to protect myself? Does anyone know an affordable service that notifies you when someone signs up for a credit card or uses your SSN?

I'm not worried at all about any of my website accounts or my computer. I know what I'm doing. I'm only worried about other people who have my data.
 

RossMAN

Grand Nagus
Feb 24, 2000
78,878
372
136
I just started working for a company that uses ADP. My SSN is in their system.. They have printed it out on documents, in full. And they still use Internet Explorer too. Not too many technical people at this job. Obviously not too concerned about privacy. Is there anything I can do to protect myself? Does anyone know an affordable service that notifies you when someone signs up for a credit card or uses your SSN?

I'm not worried at all about any of my website accounts or my computer. I know what I'm doing. I'm only worried about other people who have my data.

CreditKarma.com is free and trustworthy, worth looking into.
 

Red Squirrel

No Lifer
May 24, 2003
69,993
13,484
126
www.anyf.ca
How can they consider this a hack when it's a key logger? That's more like a virus that happens to grab passwords.. facebook password being one of them. So if you don't have the keylogger installed then you are not at risk. Hacked would be if someone managed to get into their servers and download the entire password DB.
 

destrekor

Lifer
Nov 18, 2005
28,799
359
126
How can they consider this a hack when it's a key logger? That's more like a virus that happens to grab passwords.. facebook password being one of them. So if you don't have the keylogger installed then you are not at risk. Hacked would be if someone managed to get into their servers and download the entire password DB.

We've been down that path.

Oh young grasshopper, you have much to learn about humans. They are not so wise, the filthy illiterate masses.
 

JimmiG

Platinum Member
Feb 24, 2005
2,024
112
106
Well...you can get A LOT of information about a person from Facebook at least, that could be used for identity theft.

Also, the main point is most people use 1 or 2 passwords for everything..so more than likely most of those Facebook passwords could be useful for other more dangerous areas of the persons life (such as online bank accounts etc).

Yep, Facebook gives you the answer to the "secret" question (what's the name of your school/mom/pet etc.), so if you used the same password for your Gmail, they can reset the password for any site or service you use.
 

rudeguy

Lifer
Dec 27, 2001
47,351
14
61
did they steal yahoo passwords?

I forgot mine like 10 years ago. Maybe they have it?
 

CZroe

Lifer
Jun 24, 2001
24,195
857
126
318,000 Facebook (FB, Fortune 500) accounts
70,000 Gmail, Google+ and YouTube accounts
60,000 Yahoo (YHOO, Fortune 500) accounts
22,000 Twitter (TWTR) accounts
9,000 Odnoklassniki accounts (a Russian social network)
8,000 ADP (ADP, Fortune 500) accounts (ADP says it counted 2,400)
8,000 LinkedIn (LNKD)accounts
That's 495,000. Whatever pushed the amount up to "2 million" as they claim must have been too insignificant to list despite forming the bulk of the stolen passwords.

Notably missing: PayPal.
 

Fritzo

Lifer
Jan 3, 2001
41,920
2,161
126
Massive hack? Seriously? What a misnomer and grossly errant fear-mongering statement.

That was a cumulative total, accumulated over time from organized keylogging malware that managed to get spread quite well.

If they spread malware and only have that which they directly captured from individual infections, that's not hacking.
If they obtained access into the central servers to these services and obtained a large number of credentials straight from the source... that's hacking.

Yeah, it looks like having even rudimentary antivirus protection would have prevented it from happening.
 

CZroe

Lifer
Jun 24, 2001
24,195
857
126
Yeah, it looks like having even rudimentary antivirus protection would have prevented it from happening.

They seem to be describing a rootkit keyloger that may be invulnerable to after-the-fact AV scans. If so, as long as the malware was wide-spread before its discovery, there's nothing a typical AV scan can do. The nasty rootkits even persist after a boot drive format and OS re-installation these days.
 

Zargon

Lifer
Nov 3, 2009
12,218
2
76
How can they consider this a hack when it's a key logger? That's more like a virus that happens to grab passwords.. facebook password being one of them. So if you don't have the keylogger installed then you are not at risk. Hacked would be if someone managed to get into their servers and download the entire password DB.

because its CNN Money writing the article
 

Scarpozzi

Lifer
Jun 13, 2000
26,391
1,780
126
I turned on facebook notifications. If anyone logs into my account on FB from an unrecognized device, I'm notified in an Email. ....which is basically every device except the app on my phone.

I like how they don't mention what the malware is, give it a name, or any details, yet they seem to know so much about it...
 

Red Squirrel

No Lifer
May 24, 2003
69,993
13,484
126
www.anyf.ca
"....I've never seen this screen before. Are you hacking the server?"

"No, this is called 'Device Manager.'"

Actually wasn't there a member here that got fired for "hacking"? He was using ipconfig or something like that... lol.

My cat actually hacked a laptop once, it was right in the middle of a windows install and she pulled up a command prompt. No idea what she did at the time. Turns out there's a key combination to get a command prompt for debugging purposes.
 

Ichinisan

Lifer
Oct 9, 2002
28,298
1,235
136
I turned on facebook notifications. If anyone logs into my account on FB from an unrecognized device, I'm notified in an Email. ....which is basically every device except the app on my phone.

I like how they don't mention what the malware is, give it a name, or any details, yet they seem to know so much about it...

...and how did they find out how many passwords were stolen? Were they all being stored in a place that is accessible to the public? Sophisticated malware would distribute them across a botnet.
 

Jeff7

Lifer
Jan 4, 2001
41,596
19
81
did they steal yahoo passwords?

I forgot mine like 10 years ago. Maybe they have it?


That'd be an excellent thing to say while in court.

"Well, see, I lost my password a long time ago, and Customer Service just wasn't helping. Once I found a way in, the hashes were all stored in one big folder, so I figured that if I took them all, I'd eventually find mine."



You'd probably have at least a third of the jury, and maybe one of the lawyers, asking if you could find theirs as well.



Actually wasn't there a member here that got fired for "hacking"? He was using ipconfig or something like that... lol.

My cat actually hacked a laptop once, it was right in the middle of a windows install and she pulled up a command prompt. No idea what she did at the time. Turns out there's a key combination to get a command prompt for debugging purposes.
Link. (OLD THREAD. Don't necro the old thread.)

I work (worked?) in a surveillance department. My bosses all knew that I was very competent with hardware, software, and networking so they would routinely ask me for help with things.

An IT position opened up in the department, and I was elated. I could get a $4 an hour raise for doing what i like to do.

Other associates, who were far less qualified, also put in for the position and we all had to wait for interviews.

Two days before my interview, during one of my breaks, i opened a command prompt and ran some diagnostic commands to help me understand how the network was set up. I wanted to have an edge at the interview because I could specifically talk about how our network is laid out and discuss the hardware installed on the machines.

I only used diagnostic commands.

ipconfig /all
tracert
nbtstat
netstat
arp -a

Long story short, my supervisor (whom had also put in for the position, and was far less qualified, he didnt even know how to install a wireless router in his home) turned me for "hacking the network".

HR gets involved, they don't know a damn thing about networking. They take statements from both of us. I ask them to go to IT to verify that I did nothing wrong. They don't.

Boss fires me for "tampering with surveillance equipment" while he is on vacation.

I now have no job and don't know how i am going to pay rent next month. Awesome. I have never been fired from a job in my life. I have never even been in trouble with an employer before.

On a side note, one of the other employees INSTALLED AN UNSECURED WIRELESS ROUTER ON THE CORPORATE NETWORK IN SURVEILLANCE , GOT CAUGHT, and nothing happened to him.

Is this wrongful termination? I don't know how the law works.

Updates with some FAQs:

I will not be allowed to take unemployment because i was fired for misconduct.

Getting another job in this field may not be easy because of the bad reference.

Upon conversation with another employee tonight, I learned that the boss that fired me leaked that he was going to fire me before my statement was even taken by HR.

I may have been fired for being an Atheist in the bible belt. I have proof that someone did much worse things with the network (i didn't do anything wrong) and he was promoted. He is the same religion as the boss that fired me.
http://forums.anandtech.com/showthread.php?t=2281732
 
Last edited:

highland145

Lifer
Oct 12, 2009
43,973
6,336
136


That'd be an excellent thing to say while in court.

"Well, see, I lost my password a long time ago, and Customer Service just wasn't helping. They were all in one folder, so I figured that if I took them all, I'd eventually find mine."
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |