Got an email from "have I been pwned" as I set my domain to be monitored. This is the content.
Curious, did anyone else get this? Looks like I need to go around changing all my passwords again. I JUST did this like maybe a month ago too.
By doing this I also learned that some sites have extremely terrible password security. Tripod was one of the worst offenders. My passwords were too complex and it was not accepting them. I ended up having to use a single dictionary word before it took. I don't even use a lot of those accounts anymore I need to look into what it takes to just delete them.
Some systems will also accept a complex password, but it won't actually register it, so when you go to login to test it, it does not actually work and you have it issue a reset. I don't get how that even happens, it's suppose to just be hashed anyway, so the types of characters you put or how long it is should not even matter.
In January 2019, a large collection of credential stuffing lists (combinations of email addresses and passwords used to hijack accounts on other services) was discovered being distributed on a popular hacking forum. The data contained almost 2.7 billion records including 773 million unique email addresses alongside passwords those addresses had used on other breached services. Full details on the incident and how to search the breached passwords are provided in the blog post The 773 Million Record "Collection #1" Data Breach.
Curious, did anyone else get this? Looks like I need to go around changing all my passwords again. I JUST did this like maybe a month ago too.
By doing this I also learned that some sites have extremely terrible password security. Tripod was one of the worst offenders. My passwords were too complex and it was not accepting them. I ended up having to use a single dictionary word before it took. I don't even use a lot of those accounts anymore I need to look into what it takes to just delete them.
Some systems will also accept a complex password, but it won't actually register it, so when you go to login to test it, it does not actually work and you have it issue a reset. I don't get how that even happens, it's suppose to just be hashed anyway, so the types of characters you put or how long it is should not even matter.