Close
Page 1 of 4 1234 LastLast
Results 1 to 10 of 32
  1. #1
    Zombie Slayer Zundfolge's Avatar
    Join Date
    Jul 2007
    Location
    Wichita, KS (formerly COS)
    Posts
    8,317

    Default Phishers are getting sophisticated

    So I got one of those scam emails "I hacked your email account, so send me bitcoin or I'll show the world the porn you look at" ... it had my email address and said what the password was. While that's not the PW for that email address it is one I've used other places (although not in a long time since I let LastPass generate them now).

    I think the guy doesn't have anything on me but it is disconcerting.

    My guess is he got a list of usernames (many sites use your email address) and pws and is just assuming that a lot of people use just one or two pws so he'd get lucky frightening someone. But it does illustrate why a pw manager is the way to go and you should NEVER re-use passwords.


    I downloaded my password list off LastPass and cross referenced all the sites I used that combination of password and email-address-as-username ... and found about a dozen. Only a couple of which are sites I actually use (so I changed those).



    Anyway Justin sent me the following link when I talked to him about it https://haveibeenpwned.com/ and it looks like I had been "pwned" and two of the web sites I use had been breached (disqus and plex). So glad I changed those PWs today.
    Modern liberalism is based on the idea that reality is obligated to conform to one's beliefs because; "I have the right to believe whatever I want".

    "Everything the State says is a lie, and everything it has it has stolen.
    -Friedrich Nietzsche

    "Every time something really bad happens, people cry out for safety, and the government answers by taking rights away from good people."
    -Penn Jillette

    A World Without Guns <- Great Read!

  2. #2
    QUITTER Irving's Avatar
    Join Date
    Nov 2008
    Location
    Denver, CO
    Posts
    46,527
    Blog Entries
    1

    Default

    Can you post more about LastPass? How easy is it to use? Is it a cloud thing? Do you pay for it?
    "There are no finger prints under water."

  3. #3
    Splays for the Bidet CS1983's Avatar
    Join Date
    Jan 2011
    Location
    St. Augustine, FL
    Posts
    6,260

    Default

    How is that sophisticated?

    I had an interesting one a few weeks ago when trying to sell some tires on CL. Had someone who said they wanted to buy. OK, cool. Then I get a Google Voice verification text. The guy then immediately texts he wants me to tell him the number to verify I'm real. HA! So basically they were trying to get people to verify their own phone numbers in order to get new Google voice numbers for further scams.

    I use KeePass. Free. Can export the DB. Easy to use.
    Feedback

    It is terrible to contemplate how few politicians are hanged. - The Cleveland Press, March 1, 1921, GK Chesterton

  4. #4
    Zombie Slayer Zundfolge's Avatar
    Join Date
    Jul 2007
    Location
    Wichita, KS (formerly COS)
    Posts
    8,317

    Default

    Quote Originally Posted by Irving View Post
    Can you post more about LastPass? How easy is it to use? Is it a cloud thing? Do you pay for it?
    LastPass is free and easy to use ... although they also have a "premium" version (not sure what that gives you).

    basically you set up one password to LastPass and it will automatically generate complex passwords for you and store all those passwords online so you can access them any time you need them.

    The important thing is that it allows you to use a different password on every site you log into so you aren't reusing passwords (which is bad opsec).

    https://www.lastpass.com
    Last edited by Zundfolge; 05-20-2019 at 13:19.
    Modern liberalism is based on the idea that reality is obligated to conform to one's beliefs because; "I have the right to believe whatever I want".

    "Everything the State says is a lie, and everything it has it has stolen.
    -Friedrich Nietzsche

    "Every time something really bad happens, people cry out for safety, and the government answers by taking rights away from good people."
    -Penn Jillette

    A World Without Guns <- Great Read!

  5. #5
    BANNED....or not? Skip's Avatar
    Join Date
    Jan 2013
    Location
    Highlands Ranch, CO
    Posts
    3,871

    Default

    Yup.

    Got the "we turned your webcam on" one too. I don't have a webcam on my primary dev desktop machine and my laptop is blocked out all the time. I don't do video conferencing, ever.

    Another tip I learned is to incorporate the site/name in the PW. Again, my PWs are never the same and complex but I will put the initials or short name of the site somewhere in there so if it's compromised I know which one was hit. You can still use a PW vault with this too!
    Always eat the vegans first

  6. #6
    .
    Join Date
    Jan 2013
    Location
    Florissant
    Posts
    4,380

    Default

    So, what happens when LastPass gets hacked?

  7. #7
    Nerdy Mod
    Join Date
    Jan 2012
    Location
    Colorado Springs
    Posts
    2,401

    Default

    Quote Originally Posted by davsel View Post
    So, what happens when LastPass gets hacked?
    Assuming it works like 1Password.com that I use, nothing. They don't have anything but encrypted data that even they can't decrypt. I'll give more details when I'm on a real keyboard.

    O2
    YOU are the first responder. Police, fire and medical are SECOND responders.
    When seconds count, the police are mere minutes away...
    Gun registration is gun confiscation in slow motion.

    My feedback: https://www.ar-15.co/threads/53226-O2HeN2

  8. #8
    QUITTER Irving's Avatar
    Join Date
    Nov 2008
    Location
    Denver, CO
    Posts
    46,527
    Blog Entries
    1

    Default

    Does last pass just autofill the passwords when you go to the site like Google will (if you allow)? I'll have to check it out when I get home. My current system of keeping track of passwords is likely less than desirable. What do you do for a spouse to have access in the event of your death? Keep the LastPass password written down in a separate location?
    "There are no finger prints under water."

  9. #9
    Zombie Slayer Zundfolge's Avatar
    Join Date
    Jul 2007
    Location
    Wichita, KS (formerly COS)
    Posts
    8,317

    Default

    Quote Originally Posted by Irving View Post
    Does last pass just autofill the passwords when you go to the site like Google will (if you allow)? I'll have to check it out when I get home. My current system of keeping track of passwords is likely less than desirable. What do you do for a spouse to have access in the event of your death? Keep the LastPass password written down in a separate location?
    I keep a copy of my lastpass password on a tiny slip of paper in my wallet.
    Modern liberalism is based on the idea that reality is obligated to conform to one's beliefs because; "I have the right to believe whatever I want".

    "Everything the State says is a lie, and everything it has it has stolen.
    -Friedrich Nietzsche

    "Every time something really bad happens, people cry out for safety, and the government answers by taking rights away from good people."
    -Penn Jillette

    A World Without Guns <- Great Read!

  10. #10
    QUITTER Irving's Avatar
    Join Date
    Nov 2008
    Location
    Denver, CO
    Posts
    46,527
    Blog Entries
    1

    Default

    I've heard rumors of people using realistic sounding voice recordings to say kids have been kidnapped, but nothing I can confirm. And with AI face replacement stuff scammers can and will be getting more sophisticated, but it also makes denying stuff easier IMO.
    "There are no finger prints under water."

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •