1.2 billion stolen password

1,2 billion passwords stolen, but does it affect me?

You have heard the news. Russian hackers have managed to collect a pile of no less than 1,2 billion stolen user IDs and passwords from approximately 420 000 different sites. That’s a lot of passwords and your own could very well be among them. But what’s really going on here? Why is this a risk for me and what should I do? Read on, let’s try to open this up a bit.

First of all. There are intrusions in web systems every day and passwords get stolen. Stolen passwords are traded on the underground market and misused for many different purposes. This is nothing new. The real news here is just the size of the issue. The Russian hacker gang has used powerful scripts to harvest the Internet for vulnerable systems and automatically hacked them, ending up with this exceptionally large number of stolen passwords. But it is still good that people write and talk about this, it’s an excellent reminder of why your personal passwords habits are important.

Let’s first walk you through how it can go wrong for an ordinary Internet user. Let’s call her Alice.

  1. Alice signs up for a mail account at Google. She’s lucky, alice@gmail.com is free. She’s aware of the basic requirements for good passwords and selects one with upper- and lowercase letters, digits and some special characters.
  2. Alice is quite active on the net and uses Facebook as well as many smaller sites and discussion forums. Many of them accepts alice@gmail.com as the user ID. And it’s very logical to also use the same password, it sort of belongs together with that mail address and who wants to remember many passwords?
  3. Now the evil hackers enter the scene and starts scanning the net for weak systems. Gmail is protected properly and withstands the attacks. But many smaller organizations have sites maintained on a hobby basis, and lack the skills and resources to really harden the site. One of these sites belongs to a football club where Alice is active. The hackers get access to this site’s user database and downloads it all. Now they know the password for alice@gmail.com on that site. Big deal, you might think. The hackers know what games Alice will play in, no real harm done. But wait, that’s not all.
  4. It’s obvious that alice@gmail.com is a Gmail user, so the hackers try her password on gmail.com. Bingo. They have her email, as well as all other data she keeps on the Google sites.
  5. They also scan through a large number of other popular internet sites, including Facebook. Bingo again. Now the hackers have Alice’s Facebook account and probably a couple of other sites too.
  6. Now the hackers starts to use their catch. They can harvest Alice’s accounts for information, mail conversations, other’s contact info and e-mails, documents, credit card numbers, you name it. They can also use her accounts and identity to send spam or do imposter scams, just to list some examples.

So what’s the moral of the story? Alice used a good password but it didn’t protect her in this case. Her error was to reuse the password on many sites. The big sites usually have at least a decent level of security. But if you use the same password on many sites, its level of protection is the same as the weakest site where it has been used. That’s why reusing your main mail password, especially on small shady sites, is a huge no-no.

But it is really inconvenient to use multiple strong passwords, you might be thinking right now. Well, that’s not really the case. You can have multiple passwords if you are systematic and use the right tools. Make up a system where there is a constant part in every password. This part should be strong and contain upper- and lowercase characters, digits and special characters. Then add a shorter variable part for every site. This will keep the passwords different and still be fairly easy to remember.

Still worried about your memory? Don’t worry, we have a handy tool for you. The password manager F-Secure Key.

But what about the initial question? Does this attack by the Russian hackers affect me? What should I do? We don’t know who’s affected as we don’t know (at the time of writing) which sites have been affected. But the number of stolen passwords is big so there is a real risk that you are among them. Anyway, if you recognize yourself in the story about Alice, then it is a good idea to start changing your passwords right away. You might not be among the victims of these Russian hackers, but you will for sure be a victim sooner or later. Secure your digital identities before it happens!

If you on the other hand already have a good system with different passwords on all your sites, then there’s no reason to panic. It’s probably not worth the effort to start changing them all before we know which systems were affected. But if the list of these 420 000 sites becomes public, and you are a user of any of these sites, then it’s important to change your password on that site.

 

Safe surfing,
Micke

 

More posts from this topic

winners

Why F-Secure’s the 4th Most Attractive Employer for IT Students

IT companies used to have a pretty bad image. It’s not that they’re bad companies giving people bad jobs. They just never screamed “job satisfaction” to the general public. The stereotype of IT companies as inhuman, mundane places to work became so well-known that a hilarious comedy from the 90’s called Office Space satirized the idea. The movie told the story of a disgruntled programmer who rebelled against the soulless, life-sucking office environment of the IT company he worked for in order to find happiness. The movie and the stereotype are a bit old now. But I think it’s still safe to assume that the environment represented in Office Space, and the lifestyles of the people who work there, is something everyone would like to avoid. And according to Universum – a research firm that specialized in employer branding – F-Secure is ahead of the game in offering people a place where they’d actually LIKE to work. At least according to IT students. F-Secure was ranked as the 4th most attractive employer amongst Finnish IT students in Universum’s 2016 Most Attractive Employers ranking (up from 5th in last year’s rankings), beat out only by Google, Microsoft, and Finnish game company Supercell. So what is it that makes F-Secure such an appealing employer? Well, here’s a few things we’re doing that separates us from the kind of company shown in Office Space. We don't box people into cubicles People at F-Secure aren’t expected to isolate themselves from other Fellows and sit by themselves in cubicles. Our Fellows work together in whatever way makes them feel comfortable. In fact, as a global company with offices and people working all over the world, we often think outside the box and take whatever approach lets people work together to get the best results. We don’t stop at securing computers – we secure society This sentiment, recently expressed by F-Secure Chief Research Officer Mikko Hypponen, highlights the importance of what we do at F-Secure. We deal with real adversaries and security threats, whether that’s an advanced persistent threat group working on behalf of a government, or a gang of online extortionists looking to spread ransomware or steal data to blackmail people. Having active adversaries to work against presents us with a constantly evolving set of threats to people and companies. The opportunity to combat those threats makes our days challenging, but exciting and fulfilling. We know how to chill out Cyber security is a tough business. As mentioned above, we deal with real adversaries and threats. When we’re doing our jobs, we’re focused 100% on winning. But we also understand it’s important to be able to unwind, so Fellows are encouraged to enjoy themselves at work. Our HQ has things like a sauna, a gym, games, and other things for people to enjoy when they need to step out of the fight for a few minutes. With great power comes great responsibility, but everyone needs some time to chill out (even if it’s in a scorching hot sauna). So F-Secure has a lot going for it, and based on Universum’s rankings, it looks like that’s paying off. But why don’t you tell us what’s most important to you in a workplace. Finnish IT students already think F-Secure would be a great place to work, but we’re always ready to do more. And why not check out our current openings to see if there’s a place that’s right for you. [polldaddy poll=9407357] Image: A team of Aalto University students that won an award for a software project sponsored by F-Secure. Read more here.

May 4, 2016
BY 
mikko hypponen WPFD

VIDEO: Mikko Hypponen at World Press Freedom Day

Today is World Press Freedom Day – a day created by UNESCO in recognition of the importance of free speech, as well as the important role journalists play in using this right to help inform citizens about what’s going on with the world around them. This year’s main event is being held in Helsinki, Finland, and co-hosted by the Finnish government. There was lots happening at Finlandia Hall – the event’s “ground zero”. And because Finland is home to F-Secure’s headquarters, we were there in full force to express our support for the journalists who, according to Reporters without Borders, put their privacy, freedom, and even their lives on the line to keep us all informed. Mikko Hypponen, F-Secure’s Chief Research Officer, delivered a keynote address ahead of a discussion called “Protecting your rights: Surveillance Overreach, Data Protection, and Online Censorship”. “But right now, over the last couple of years, the biggest changes in this field have not been with online crime. They’ve been with governments entering the online, cyber attack business,” Hypponen told the audience. [youtube https://www.youtube.com/watch?v=l4InPx7xraI?start=754] After his speech, Mikko shared some additional thoughts on Apple vs. the FBI, and World Press Freedom Day. [youtube=https://www.youtube.com/watch?v=BBINozrQGlc&w=420&h=315] Sean Sullivan was also there, along with one of F-Secure Labs’ forensic analysts to help journalists check their devices, and provide security tips on how they can protect their data. “Without privacy, we can’t have free press. And without a free press, we cannot have democracy. And without democracy, we cannot have freedom,” Mikko told the audience. And that’s not just rhetoric – it’s something we’re backing up. Any journalist interested in using encryption to protect themselves against unwanted surveillance can get in touch with us before May 15 to get a free, 3-device, 12-month subscription for F-Secure's Freedome VPN, which lets users encrypt their communications, block tracking attempts and malicious websites, and change their virtual location. All journalists need to do is send a confirmation of their valid press credentials (for example, an image) by direct message to our Twitter feed (@FSecure) before May 15. Edited to add: We also caught a panel discussion about digital threats to journalists with F-Secure Cyber Security Advisor Erka Koivunen, Tanzanian journalist and newspaper editor Dennis Msacky, and University professor, writer and journalist Hanna Nikkanen. [youtube=https://www.youtube.com/watch?v=WYifFDj2UaI&w=420&h=315]

May 3, 2016
BY 
842710939_d8f092ed9f_b (1)
April 28, 2016
BY