After “Mother of All Breaches,” Update Passwords on Compromised Sites

January’s big security news was the Mother of All Breaches, the release of a massive database containing 26 billion records built from previous breaches across numerous websites, including Adobe, Dropbox, LinkedIn, and Twitter. It’s unclear how much of the leaked data is new, but it’s a good reminder to update your passwords for accounts on compromised sites, especially those you reused on another site. Cybernews has a leak checker that reports which breached sites include your data.

Apple also has a tool for you that can help.  Now that Passwords is one of the system settings on your Mac or iOS device you can click on “Security Recommendations”  and the Password AutoFill passwords list in iOS, iPadOS, and macOS indicate which of a your saved passwords will be reused with other websites, passwords that are considered weak, and passwords that have been compromised by a data leak.

  • Passwords are marked reused if the same password is seen used for more than one saved password across different domains.

  • Passwords are marked weak if they may be easily guessed by an attacker. iOS, iPadOS, and macOS detect common patterns used to create memorable passwords, such as using words found in a dictionary, common character substitutions (such as using “p4ssw0rd” instead of “password”), patterns found on a keyboard (such as “q12we34r” from a QWERTY keyboard), or repeated sequences (such as “123123”). These patterns are often used to create passwords that satisfy minimum password requirements for services, but are also commonly used by attackers attempting to obtain a password using brute force.Because many services specifically require a four- or six-digit PIN code, these short passcodes are evaluated with different rules. PIN codes are considered weak if they are one of the most common PIN codes, if they are an increasing or decreasing sequence such as “1234” or “8765,” or if they follow a repetition pattern, such as “123123” or “123321.”
  • Passwords are marked leaked if the Password Monitoring feature can claim they have been present in a data leak.

 More generally, password managers often have a feature that checks your passwords against the Have I Been Pwned database of breaches and helps you change compromised passwords—1Password’s is called Watchtower, shown below.You can also search Have I Been Pwned directly. Don’t panic if your email address appears in numerous breaches because some of the theoretically compromised accounts may be defunct sites, trivial sites you used once 10 years ago, or duplicate password manager entries for a site whose password you already updated.

(Featured image by iStock.com/Prae_Studio)

Similar Posts

  • When Should You Subscribe to AppleCare?

    With Apple’s recent launch of AppleCare One, which covers multiple devices, and updates to its traditional AppleCare+ plans, you might be wondering what…

  • It is getting quite warm down here and I have had to fiddle with my solar heating system for the pool to get it turned down so I don’t have a hot tub instead of a refreshing plunge pool. One thing that is surprising here in Florida in my estimation is the lack of solar energy installations. Seldom do you see solar PV arrays either on rooftops or as a solar farm and even my rudimentary solar heating system for my pool is somewhat unique. You would think with all the sun down here…

    I am doing some upgrades and maintenance on the motorcycles this weekend. I do enjoy motorcycle mechanics, well, most of the time. It may seem frustrating to some but freeing a stuck bolt or troubleshooting that backfiring is actually relaxing for me even as I sweat it out. Anyone need a really clean 2009 S150 Vespa?

    Thank you for reading this issue of Kibbles & Bytes!

    Your Kibbles & Bytes Team,

    _Don, Emily & Hadley_

  • This is the craziest Presidential election cycle that I have seen. I first got involved when President Johnson was running against Barry Goldwater and that seemed pretty crazy especially after I lost faith with the President over Vietnam. But this time it would be great comedy if the stakes were not so serious. I have to tell you that seeing Donald Trump ask people to raise their hands in a pledge is one of the scariest things I have seen in a long time.

    Voting is so important and our system is messy with primaries, caucuses, super delgates and conventions but it is also the basis of our democracy. I am proud to say that the Vermont legislature passed an automatic voter registration bill unanimously this week, meaning when you get a driver’s license you are automatically registered to vote. You really do not have the right to complain about your leaders if you do not get out and vote. So, exercise your right and go to the polls when the circus comes to your state!

    Thank you so much for reading this issue of Kibbles & Bytes!

    Your Kibbles & Bytes Team,

    _Don, Emily & Hadley_