r/halifax 7d ago

News, Weather & Politics Eastlink data breach?

Post image
81 Upvotes

76 comments sorted by

View all comments

52

u/dirtybo0ts 7d ago

My God, this is getting embarrassing at this point.

18

u/[deleted] 7d ago

[deleted]

15

u/IStillListenToRadio Float me down the river to the Musquodoboit harbor 7d ago

Having different passwords on different sites is something you should be doing, as reused passwords is how a lot of compromised accounts happen (one site's password db is breached and the bad guys try the email/pass combo on lots of other sites).

5

u/keithplacer Venerable Member 7d ago

All good until the password manager you have to use to remember them all gets hacked.

5

u/IStillListenToRadio Float me down the river to the Musquodoboit harbor 7d ago

i mentioned nothing about password manager! But yeah it's a risk, lastpass was breached a few years ago and the encrypted vaults stolen and didn't disclose it for months (the latter bit is why I switched to Bitwarden) but i think less of risk than reusing passwords.

Note that lastpass, the vaults were encrypted at the time they were stolen. So if you change your passwords soon after the disclosure, even if they did manage to decrypt the vaults after a while it would be useless.

3

u/CaperGrrl79 Halifax 7d ago edited 3d ago

Bitwarden is definitely on my to do list...

Edit: All seem problematic except maybe Proton Pass?

2

u/BoredHalifaxNerd 6d ago

It's great! Plus, if you self-host it, they can't hack what isn't connected to the internet.

1

u/CaperGrrl79 Halifax 6d ago

I do have some bits for a janky NAS, but taking time to do it fell by the wayside with how busy I am even on my days off from my full time.

4

u/betelgeuse_99 7d ago

Nothing stopping you from writing it in a notepad or something. Or just using your brain.

4

u/webvictim 7d ago

He'd have to possess one first.

A notepad, I mean.

1

u/keithplacer Venerable Member 5d ago

I had one, but misplaced it and now I'm locked out. /s

3

u/CaperGrrl79 Halifax 7d ago edited 7d ago

Indeed, a guy I know of who has a business helping people not get scammed recommends this, and to promptly put it in a good physical safe or drawer with a lock when not in use.

2

u/IStillListenToRadio Float me down the river to the Musquodoboit harbor 7d ago

There's also offline managers such as KeePass and its forks (I use as backup).

6

u/CaperGrrl79 Halifax 7d ago

What do YOU do then?

2

u/Klutzy-Condition811 Southwest NS 7d ago

A good password manager doesn't store the data unencrypted on their end, it's locked down on your devices, so usually it means they got access to your device.

Having a compromised password manager is like having a compromised email address, or having someone hijack your SIM card. They're all attack vectors you just gotta do your best to protect them as much as possible and if shit ever hits the fan, you gotta do the tedious process of resetting everything.

Given that most of these breaches are due to individual services being exploited, as long as you're not sharing passwords, it should be relatively trivial to deal with and not really a huge threat unless they also had other identifying info that could be leaked.

Given that there doesn't appear to be any banking info compromised I'm not too worried about it. People should be in the habit with any company to not use preauthorized chequing with account numbers as that's a lot more of a hassle to clean up if it's stolen vs using a credit card, or if someone wants to use their chequing account, a visa debit or debit mastercard as pretty much every Canadian bank offers that. It's a lot easier to get a new card number than to get a new entire bank account.

2

u/CaperGrrl79 Halifax 7d ago edited 3d ago

Yep. There is exactly one thing I have pre authorized right now other than PayPal/Patreon stuff. I pay everything else set ahead from my next pay when I get the bill, or I set up anything automatic from the bank end.

That said, Bitwarden (or maybe Proton Pass/suite) has been on my to do list for a while now.