Security News Is this legit? Password leak news

Acadia

Level 2
Thread author
Sep 25, 2020
61

SpiderWeb

Level 13
Verified
Top Poster
Well-known
Aug 21, 2020
608
Anyone signed up to any service online should assume that a password that they use is on this list. Cybersecurity researchers recommend that users update their passwords and enable multi-factor authentication wherever possible.
Wonderful...
 

SpiderWeb

Level 13
Verified
Top Poster
Well-known
Aug 21, 2020
608
I read more about this. Interesting notes. So this password data file has been around since 2021. It's just passwords. They are not linked to anything, not accounts, not websites, not numbers. Just passwords. So it's kinda useless. It might help the NSA or something very sophisticated to narrow down how many passwords to try in a brute force attack, or some researcher who wants to study trends in passwords. But, as long as you use a unique password for every single service it is going to be a nightmare for anybody to break into your accounts because they are just plain passwords. Not salts, no rules, no bells or whistles on how the passwords get encrypted.
 

Acadia

Level 2
Thread author
Sep 25, 2020
61
I read more about this. Interesting notes. So this password data file has been around since 2021. It's just passwords. They are not linked to anything, not accounts, not websites, not numbers. Just passwords. So it's kinda useless. It might help the NSA or something very sophisticated to narrow down how many passwords to try in a brute force attack, or some researcher who wants to study trends in passwords. But, as long as you use a unique password for every single service it is going to be a nightmare for anybody to break into your accounts because they are just plain passwords. Not salts, no rules, no bells or whistles on how the passwords get encrypted.
Thanks for that.
Acadia
 

jackuars

Level 28
Verified
Top Poster
Well-known
Jul 2, 2014
1,715
This isn't new. There was Rockyou2021 before that. If you want to download the file, it's available here:
rockyou2021.txt: A Short Summary & Torrent Download | tweedge's blog.

It's around 12GB to download and 90GB+ when uncompressed.

By the way it's nothing to be paranoid about, unless you use the same password across all websites.

"
rockyou2021.txt is not: a breach, a list of breached passwords, anything substantively new, or a sufficient reason to change your passwords (on its own).

rockyou2021.txt is: a wordlist which includes mostly English-language words, possible passwords, and known breached passwords. All of which was known & publicly available prior to this point. It can be sometimes useful as a wordlist for password cracking, though!

You should: take this time to identify news sources which used fearmongering to draw readers in on this subject in instead of facts, and unfavorite/unsubscribe from/block those sources."
 
Last edited:

blackice

Level 39
Verified
Top Poster
Well-known
Apr 1, 2019
2,867
I read more about this. Interesting notes. So this password data file has been around since 2021. It's just passwords. They are not linked to anything, not accounts, not websites, not numbers. Just passwords. So it's kinda useless. It might help the NSA or something very sophisticated to narrow down how many passwords to try in a brute force attack, or some researcher who wants to study trends in passwords. But, as long as you use a unique password for every single service it is going to be a nightmare for anybody to break into your accounts because they are just plain passwords. Not salts, no rules, no bells or whistles on how the passwords get encrypted.
Yeah it’s mostly used for credential stuffing attacks, which is how most people lose accounts. Shared passwords between multiple services.
 

bazang

Level 6
Jul 3, 2024
298
By the way it's nothing to be paranoid about, unless you use the same password across all websites.
Of course but the average digital device user does not know that and the online media world knows this and they exploit it for click and rage bait generated traffic.

Clicks Matter
#clicksmatter

Yeah it’s mostly used for credential stuffing attacks, which is how most people lose accounts. Shared passwords between multiple services.
Peoples' ignorance makes the online media a lot of click-generated revenue. Just look at why this thread was created - because OP did not know if it was real and then other paranoia-driven posts were made. A few were already hooked into the implied narrative that user passwords are as good as exposed, easily obtainable plaintext.

The easiest thing in the world is to exploit a person's and\or peoples' ignorance. It has been highly effective since before recorded history.
 
  • Like
Reactions: mlnevese

Acadia

Level 2
Thread author
Sep 25, 2020
61
Peoples' ignorance makes the online media a lot of click-generated revenue. Just look at why this thread was created - because OP did not know if it was real and then other paranoia-driven posts were made. A few were already hooked into the implied narrative that user passwords are as good as exposed, easily obtainable plaintext.

The easiest thing in the world is to exploit a person's and\or peoples' ignorance. It has been highly effective since before recorded history.
That's why we, well I anyway, come to MalwareTips, to get rid of my ignorance and learn.
Acadia
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top