News: 1640070612

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK National Crime Agency finds 225 million previously unexposed passwords

(2021/12/21)


The United Kingdom’s National Crime Agency and National Cyber Crime Unit have uncovered a colossal trove of stolen passwords.

We know this because Troy Hunt, of Have I Been Pwned (HIBP) fame, yesterday [1]announced the agency has handed them over to his service, which lets anyone conduct a secure search of stolen passwords to check if their credentials have been exposed.

The NCA shared 585,570,857 with HIBP, and Hunt said 225,665,425 were passwords that he hasn’t seen before in the 613 million credentials HIBP already stored before the NCA handed over this new batch.

[2]

The NCA sent Hunt a statement explaining how it found the passwords:

During recent NCA operational activity, the NCCU’s Mitigation@Scale team were able to identify a huge amount of potentially compromised credentials (emails and associated passwords) in a compromised cloud storage facility. Through analysis, it became clear that these credentials were an accumulation of breached datasets known and unknown.

The fact that they had been placed on a UK business’s cloud storage facility by unknown criminal actors meant the credentials now existed in the public domain and could be accessed by other 3rd parties to commit further fraud or cyber offences.

The NCA’s statement to Hunt did not reveal the source of the password trove, or how it was discovered. Hunt did reveal the following were found among the newly compromised passwords.

flamingo228

Alexei2005

91177700

123Tests

aganesq

Today's release brings the total Pwned Passwords count to 847,223,402, a 38 percent increase over the last release. 5,579,399,834 occurrences of a compromised password are represented across HIBP.

[3]Have I Been Pwned goes open source, bags help from FBI

[4]3D printing site Thingiverse suffers breach of 228,000 email addresses amid sluggish disclosure

[5]Hole blasted in Guntrader: UK firearms sales website's CRM database breached, 111,000 users' info spilled online

Hunt’s post also announced that HIBP’s new ingestion pipeline is now live and enables mass uploads of compromised passwords by law enforcement agencies. The FBI is already in on the action. ®

Get our [6]Tech Resources



[1] https://www.troyhunt.com/open-source-pwned-passwords-with-fbi-feed-and-225m-new-nca-passwords-is-now-live/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YcGz5GRDdFSzw7rSO0ITlAAAAMY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2021/06/01/in_brief_security/

[4] https://www.theregister.com/2021/10/14/thingiverse_data_breach_228k_email_addresses/

[5] https://www.theregister.com/2021/07/23/guntrader_hacked_111k_users_sql_database/

[6] https://whitepapers.theregister.com/



Trust

Skiron

I dunno if I trust typing one of my many passwords on that site to check it...

Re: Trust

nagyeger

It's fairly low risk. from your favourite shell:

From the API docs: (https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByRange)

Searching by range

In order to protect the value of the source password being searched for, Pwned Passwords also implements a k-Anonymity model that allows a password to be searched for by partial hash. This allows the first 5 characters of a SHA-1 password hash (not case-sensitive) to be passed to the API:

GET https://api.pwnedpasswords.com/range/{first 5 hash chars}

It will also add a random 800-1000 hashes if you request padding (next item in docs)

Re: Trust

Flocke Kroes

Thanks. I looked at the source code for the web page, saw Google Analytics and left in disappointment. The API has an attack surface small enough for me to have confidence in it (watch out for .bash_history). Now I know my most important passwords have not reached haveibeenpwned.

Re: Trust

Anonymous Coward

It's alright, I'll type it in for you...

No, you're OK, your password hasn't leaked.

.

Oh thanks, mine's the one with 'Skiron' written on the label.

Re: Trust

Phones Sheridan

Indeed, I've often wondered if this site could be being used as a resource by either hackers or states. Remember Lavabit, Truecrypt, Tor and Proton Mail were considered safe by their fans, quite fanatically, until it turned out they actually were not. Lavabit was in the process of being forced to install traffic sniffers into their network, Truecrypt were being co-erced, Tor had so many government controlled nodes there was no anonymity and Proton Mail removed one of it's privacy promises off it's website following a court order. If Haveibeenpwned was being compelled by it's government, it probably couldn't tell us overtly.

A database of known passwords and usernames, is highly valuable because it probably indicates just how un-unique most peoples passwords are. Geeks will probably point out that mathematically there are trillions of user / password combinations possible for a particular application and it would take millions of years to crack them. This trove probably narrows that down to hundreds of millions making the timescales more reasonable, if it doesn't already have your exact login names and password to start with. Combine this with a google like ability to match data to actual people and the ability to predict your actions and the way you think better than you can yourself there is no actual privacy out there.

The 50 or so active commentards on this site will proclaim that their passwords are indeed truly random or for some technical reason the event of them being cracked or discovered is highly improbable. My response is you are not and never will be the target, and if you were, I would point to exhibit a... The pipe wrench, and exhibit b.. you're probably not that interesting.

Re: Trust

boblongii

You need to bear in mind that these passwords (and many others) are already being passed around by the bad guys, so it's a resource only in the sense that it might be a sort of external backup for them.

Re: Trust

Korev

For a while I got spam from addresses given to (later) compromised websites claiming my computer had been hacked and here's your password to prove it and they needed me to pay them money...

I don't know if the spammers bought the details somewhere or if they got them from sites like these. Either way, using a unique email address for everywhere (and a password manager) means I can easily block the compromised addresses.

What they claimed I'd been up to -->

Not suprised

Don Dumb

How many of these are stolen from UK ISPs? - several appear to not store passwords in salted and hashed form at rest, even using them for verifction when you phone up.

Going against both ICO & NCSC guidance but somehow claiming in public "that's fine".

hackers*2

Anonymous Coward

Frequently when a list of "hacked" accounts is released, our mail-server starts seeing login attempts for non-existent accounts that have just appeared in the new list. So I think that a significant number of the hacked account details in these lists sold on the dark web have been invented to scam the scammers buying the original hacked lists.

Virtue would go far if vanity did not keep it company.
-- La Rochefoucauld