Troy Hunt(@troyhunt) 's Twitter Profile Photo

Alrighty CommBank, who over there wants to take a shot at fixing this? Suggesting that one of the most important passwords you have should be kept in the weakest storage unit you have (your brain) is nonsensical. commbank.com.au/articles/busin…

Alrighty @CommBank, who over there wants to take a shot at fixing this? Suggesting that one of the most important passwords you have should be kept in the weakest storage unit you have (your brain) is nonsensical. commbank.com.au/articles/busin…
account_circle
Troy Hunt(@troyhunt) 's Twitter Profile Photo

This is some cool research by Philippe Teuwen on how someone that can observe Pwned Passwords requests (namely Cloudflare or me) could possibly derive the original password if the search is performed incrementally (char by char): blog.quarkslab.com/passbolt-a-bol…

account_circle
Julien Cayzac(@juliencayzac) 's Twitter Profile Photo

I keep getting those.

My password is long, random, unique, not pwned & set as required for any login.

I have no clue what's happening. Troy Hunt any idea?

I keep getting those.

My password is long, random, unique, not pwned & set as required for any login.

I have no clue what's happening. @troyhunt any idea?
account_circle
whywhat(@eatery1234) 's Twitter Profile Photo

Troy Hunt i recommend using 4999 because it's right in the middle, so if someone starts at 0000, they have to do 5000 guesses, and if they start at 9999, they have to do 5000 guesses before they guess your password right

account_circle
Troy Hunt(@troyhunt) 's Twitter Profile Photo

7M seems to be a small subset of the overall impacted customer base, do breached former AT&T customers not get access to this? tech.co/news/att-data-…

account_circle
Troy Hunt(@troyhunt) 's Twitter Profile Photo

Unfortunately I couldn't get in touch with anyone at T2 before this hit the press, tried via both contact form and LinkedIn (someone in a capacity who'd definitely be dealing with this incident) 4 days ago to no avail. The Cyber Daily author also reached out for comment.

account_circle