120 Compromised Pas...
 

MegaSack DRAW - This year's winner is user - rgwb
We will be in touch

[Closed] 120 Compromised Passwords

27 Posts
20 Users
0 Reactions
94 Views
Posts: 3747
Free Member
Topic starter
 

Been ignoring this message from google for months but should really sort it. Do I really have to change them one by one or will something like lastpass help?


 
Posted : 18/01/2021 6:22 pm
Posts: 947
Full Member
 

Hmm, following this, I have a mere 67 to sort out


 
Posted : 18/01/2021 6:24 pm
Posts: 3747
Free Member
Topic starter
 

loads of them I can probably delete anyway, they're from defunct websites etc, but it's still a faff


 
Posted : 18/01/2021 6:36 pm
Posts: 31206
Full Member
 

The real danger is the passwords for compromised/defunct sites that you have re-used for non-compromised active sites.


 
Posted : 18/01/2021 6:38 pm
Posts: 23296
Free Member
 

^^^

That. My iCloud account got hacked from a long defunct last.fm account.

Fortunately i was online as it happened and got it back in a couple of minutes.


 
Posted : 18/01/2021 6:56 pm
Posts: 2213
Free Member
 

How do you find out how many compromised passwords you have?


 
Posted : 18/01/2021 7:01 pm
Posts: 23296
Free Member
 

The latest iOS and I’m assuming android tells you if any of the passwords it stores are on compromised lists.

Or try haveibeenpwned.com


 
Posted : 18/01/2021 7:04 pm
Posts: 2213
Free Member
 

Ah, okay. Looks like I'm clear for now. Had a weird hacking issue last year and lost access to my google account and had to start from scratch as it wouldn't let me reset it (they didnt believe I was me even though I had two factor authentication and was able to put the code they texted me in).

I'm much more careful now.


 
Posted : 18/01/2021 7:23 pm
Posts: 17854
Full Member
 

The latest iOS and I’m assuming android tells you if any of the passwords it stores are on compromised lists.

Does it flash that up in neon like intensity or do you have to ask?


 
Posted : 18/01/2021 8:13 pm
Posts: 3747
Free Member
Topic starter
 

A big pop up appears, can’t miss it. Mine does it whenever I log into google with chrome.


 
Posted : 18/01/2021 8:49 pm
Posts: 3190
Free Member
 

I use 1Password. It's good, I like it - chose it because it integrates into all the devices I use, including work. it also tells you which sites offer two-factor authentication that you haven't activated.

I used to be part of the "use the same password for everything" brigade until it was explained why that was such a bad idea!

It took me a while to sort everything out after getting 1password - as above, prioritize those accounts which would be most serious if they got hacked - email, paypal, amazon etc.


 
Posted : 19/01/2021 12:35 am
Posts: 2980
Free Member
 

I recently discovered I had over 200 compromised passwords, however I've changed the most critical ones over to a new 20+ character formula that is different for each website.

According to a password checking website my old password would be hacked in under a minute. A password similar to my new one 19 septillion years....

Even ones restricted by no special characters and limited to under 10 characters would take 2000 years to crack by a computer.

I've started using a VPN 24/7 too. I use lots of public networks unfortunately.


 
Posted : 19/01/2021 8:33 am
Posts: 6310
Full Member
 

One good reason to despise online retailers that force you to create an account rather than allowing checkout as guest 😡


 
Posted : 19/01/2021 8:40 am
Posts: 0
Free Member
 

Latest versions of Chrome suggest a password for you, since Chrome itself stores those passwords you don't have to remember them. Of course it's a pain if you decide to use a different browser to access one of those services.

I think I've eight "compromised" passwords but they are actually development passwords local to my machine.


 
Posted : 19/01/2021 9:35 am
Posts: 31206
Full Member
 

it’s a pain if you decide to use a different browser to access one of those services.

I have Chrome on my phone specifically just so I can check what my stored password is when logging in somewhere on a different browser 😁


 
Posted : 19/01/2021 9:38 am
 IHN
Posts: 19878
Full Member
 

This is a job I keep meaning to do. I've changed my Google account password to something 'secure' (19 characters, alphanumeric mix), but I should really do the rest, as they're all pretty much between two others, one not very secure, one very not secure.

One good reason to despise online retailers that force you to create an account rather than allowing checkout as guest

Amen, brother. Especially the ones that make you choose some mentally long alphanumeric/special character/mixed case combination to, I dunno, buy a toilet brush.


 
Posted : 19/01/2021 9:44 am
Posts: 11377
Full Member
 

I've got a few flagged, all of them seem to be sites that no longer exist (which is kind of good news). I do need to have a clear out though as it looks like I've a massive list of sites that I have accounts that I no longer use and could probably do with killing the account (if possible).


 
Posted : 19/01/2021 9:48 am
Posts: 77699
Free Member
 

One good reason...

Not really.

If you want to check out as 'guest' then it's probably a one-time purchase in which case it doesn't matter if you don't remember the password. If that's not the case, use a password manager. There's a couple of good suggestions here and there's likely one literally baked into your browser. I don't know what probably two thirds of my website passwords are.

Especially the ones that make you choose some mentally long alphanumeric/special character/mixed case combination to, I dunno, buy a toilet brush.

"I'mBuyingAToiletBrush!" would be a fantastic password.

(Ruined it now though, sorry)


 
Posted : 19/01/2021 9:56 am
Posts: 13421
Full Member
 

I went through this recently and discovered I had passwords stored for sites I had no memory of ever visiting. I cleared / reset them and now just use WCAPassword£ for all websites


 
Posted : 19/01/2021 9:59 am
Posts: 8707
Full Member
 

Especially the ones that make you choose some mentally long alphanumeric/special character/mixed case combination

Yeah, always a hassle logging in when I can’t remember whether it is password, Password, Password1 or Password1!  Life has just got so complicated 🙁


 
Posted : 19/01/2021 10:05 am
Posts: 13594
Free Member
 

One good reason to despise online retailers that force you to create an account rather than allowing checkout as guest 😡

Even the ones offering Paypal which still insist on you manually entering an address even thuogh they have to use the one PP gives them.

Then there's the ones which insist on you filling in the County, WTF - utterly pointless.

So many cray shop front designs in circulation.

I just use PP for everything, if the site doesn't take PP, they don't get my custom (bar Amazon).


 
Posted : 19/01/2021 10:07 am
Posts: 1736
Free Member
 

SAme position - 60ish I think at last count and been burying my head in the sand... Guess I need to sign up to 1password or something. Any other recommendations for something that works across laptop and iPhone??


 
Posted : 19/01/2021 10:11 am
Posts: 0
Free Member
 

@Cougar - as above, I use the one now built into Chrome. The only one I really need to remember is the one for Chrome itself which is an eleven, err, thirteen, err, err, .....

The only site I don't use it for is for banking and I then use the provided PIN sentry device. There's also a few, like HMRC, that use 2-factor authentication, so password and second device.

Ultimately the weakest link in all of this is us.


 
Posted : 19/01/2021 10:12 am
Posts: 4331
Full Member
 

Any other recommendations for something that works across laptop and iPhone??

I’ve just gone through this. If you use Chrome on the laptop and iPhone then you can use Chrome to manage passwords on both. It’s a faff going through and changing passwords (using chrome to suggest new ones) but now it’s set up it’s easy & seems to be working well.


 
Posted : 19/01/2021 10:19 am
Posts: 6310
Full Member
 

@cougar - yeah but when you go back a couple of years later and have no recollection of using them before.. so customers just end up using the one password they can remember...


 
Posted : 19/01/2021 10:22 am
Posts: 7185
Full Member
 

Of course it’s a pain if you decide to use a different browser to access one of those services.

If you're on iOS, you can use Chrome as one of your password stores (in addition to the one baked into iCloud).


 
Posted : 19/01/2021 10:29 am
Posts: 493
Free Member
 

I use KeePass & Chrome and put 2fa on anything that supports it. Someone opened a PayPal credit card in my name and although it had nothing to do with my (then patchy) approach to passwords etc, it spooked me sufficiently to take action.
Which reminds me, might be time to back up my phone. In case there's a problem with Google drive...
The master password for KeePass (though mostly I use thumbprint) and the backup codes printouts are in a notebook in my safe.


 
Posted : 19/01/2021 11:39 am
Posts: 17854
Full Member
 

Well on the back of this I trawled through all the passwords in Keychain Manager, reset a fair few and deleted some accounts I didn't even know I had.


 
Posted : 19/01/2021 1:24 pm