<?xml version="1.0"?>
<rss version="2.0">
	<channel>
		<title>TINS breach</title>
		<link>http://www.allegro.cc/forums/view/618345</link>
		<description>Allegro.cc Forum Thread</description>
		<webMaster>matthew@allegro.cc (Matthew Leverton)</webMaster>
		<lastBuildDate>Fri, 22 Jan 2021 02:51:36 +0000</lastBuildDate>
	</channel>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>So did anyone know/realize that TINS accounts were breached and leaked online?</p><p><span class="remote-thumbnail"><span class="json">{"name":"612848","src":"\/\/djungxnpq2nug.cloudfront.net\/image\/cache\/b\/8\/b8adb037021fa62ea11c7972d899ab97.png","w":593,"h":112,"tn":"\/\/djungxnpq2nug.cloudfront.net\/image\/cache\/b\/8\/b8adb037021fa62ea11c7972d899ab97"}</span><img src="http://www.allegro.cc//djungxnpq2nug.cloudfront.net/image/cache/b/8/b8adb037021fa62ea11c7972d899ab97-240.jpg" alt="612848" width="240" height="45" /></span>
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Chris Katko)</author>
		<pubDate>Wed, 20 Jan 2021 13:11:50 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>Passwords in the TINS database are hashed and salted. There is no cleartext. Therefore a breach is unlikely.</p><p>Of course I can&#39;t be sure that I prevented every possible attack. Where did you see this? Please show me some more information so I can investigate.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (amarillion)</author>
		<pubDate>Wed, 20 Jan 2021 13:23:28 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>I assume it&#39;s saying <i>his</i> password from TINS was found in a data dump. If it&#39;s a unique, random password, then it&#39;s unlikely that it came from elsewhere.</p><p>I just act as if all passwords on all sites are in the public domain, and I rotate ones I care about and/or enable TFA. And every password of mine is completely randomly generated.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Matthew Leverton)</author>
		<pubDate>Wed, 20 Jan 2021 23:21:56 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>I really do want to know more about this. I could check my own password for example.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (amarillion)</author>
		<pubDate>Thu, 21 Jan 2021 13:37:16 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>It showed in my Chrome (google checks against known breaches).</p><p>You can also check if your e-mails (or all e-mails in your database) show up as flagged in haveibeenpwned.com</p><p>I don&#39;t believe Google tells you the specific breach. It is possible that it&#39;s not breached, like Matt said, and a common e-mail and password were stored in chrome, that then flagged. As in, anywhere I used my e-mail and that password, would show up in that Chrome warning menu.</p><div class="quote_container"><div class="title"><a href="http://www.allegro.cc/forums/thread/618345/1049125#target">Matthew Leverton</a> said:</div><div class="quote"><p>
 If it&#39;s a unique, random password
</p></div></div><p>
I doubt it&#39;s unique though I don&#39;t remember it.</p><p>But Matthew is probably right. I used to use passwords common to multiple websites before you know... everyone got hack crazy.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Chris Katko)</author>
		<pubDate>Thu, 21 Jan 2021 14:26:43 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>Ok, I checked a few email addresses in the TINS database against haveibeenpwned.com. Some of them are green, some of them are red. It doesn&#39;t look like the whole site was breached. It looks like indeed that this is just a re-used password.</p><p>At this point I won&#39;t take additional security precautions, unless somebody feels strongly otherwise.
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (amarillion)</author>
		<pubDate>Thu, 21 Jan 2021 14:36:25 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p>If I go to passwords.google.com it lists both allegro.cc and amarillion.org under &quot;reused passwords&quot; <img src="http://www.allegro.cc/forums/smileys/tongue.gif" alt=":P" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (Elias)</author>
		<pubDate>Fri, 22 Jan 2021 02:20:41 +0000</pubDate>
	</item>
	<item>
		<description><![CDATA[<div class="mockup v2"><p><span class="remote-thumbnail"><span class="json">{"name":"612855","src":"\/\/djungxnpq2nug.cloudfront.net\/image\/cache\/1\/0\/10d4e39672f2daf65940fac7f5d84d51.png","w":952,"h":412,"tn":"\/\/djungxnpq2nug.cloudfront.net\/image\/cache\/1\/0\/10d4e39672f2daf65940fac7f5d84d51"}</span><img src="http://www.allegro.cc//djungxnpq2nug.cloudfront.net/image/cache/1/0/10d4e39672f2daf65940fac7f5d84d51-240.jpg" alt="612855" width="240" height="103" /></span></p><p>Coincidentally I finally got around to cleaning up saved passwords in Firefox and Chrome, and moved them all over to LastPass instead. Then using LastPass I generated new, long, complex passwords for all the things, one-by-one.</p><p>LastPass&#39;s code to automatically generate new passphrases for known services appears to be broken for years now (according to threads I found online anyway). I started around 11 AM and didn&#39;t finish until like 4 AM (with undefined breaks and distractions in between). <img src="http://www.allegro.cc/forums/smileys/tongue.gif" alt=":P" /> Which is why I had put it off so long.</p><p>I&#39;ve only been using a [cloud/mobile] password manager for about a year now. And I only finally switched fully to it literally today. In theory, I&#39;m reasonably safe now. In practice, you only have to break one passphrase (well, and 2fa<sup>1.7n</sup>) to get everything that I have.</p><p>The passwords that are duplicated are for cross-platform apps that require me to type in a password to log in from the TV or game console or what have you. I didn&#39;t want to have to try to type a 48 character password by glancing at my phone (which sleeps every few seconds, requiring my fingerprint to unlock, and I think even LastPass locks in that case again). So I came up with a reasonably secure passphrase that is sufficiently random and complex that I can easily remember, and that my wife will be able to type if necessary. It&#39;s shared to make it easy because the worst thing is when you&#39;re uncertain which passphrase you used... And for the things I&#39;m using it for I can just call the company and yell at them if my account ever gets hijacked (and if they&#39;re utilizing services I&#39;m paying for and not using then I guess who cares).</p><p>Unfortunately, now if LastPass goes down (or I get amnesia or otherwise permanent memory loss) I&#39;m <span class="cuss"><span>fuck</span></span>ed. <img src="http://www.allegro.cc/forums/smileys/tongue.gif" alt=":P" />
</p></div>]]>
		</description>
		<author>no-reply@allegro.cc (bamccaig)</author>
		<pubDate>Fri, 22 Jan 2021 02:51:36 +0000</pubDate>
	</item>
</rss>
