A digital form of protest could become the go-to response for the world’s largest porn website as it faces increased regulations: Not letting people access the site.
In March, PornHub blocked access to visitors connecting to its website from Texas. It marked the second time in the past 12 months that the porn giant shut off its website to protest new requirements in online age verification.
The Texas law, which was signed in June 2023, requires several types of adult websites to verify the age of their visitors by either collecting visitors’ information from a government ID or relying on a third party to verify age through the collection of multiple streams of data, such as education and employment status.
PornHub has long argued that these age verification methods do not keep minors safer and that they place undue onus on websites to collect and secure sensitive information.
The fact remains, however, that these types of laws are growing in popularity.
Today, Lock and Code revisits a prior episode from 2023 with guest Alec Muffett, discussing online age verification proposals, how they could weaken security and privacy on the internet, and whether these efforts are oafishly trying to solve a societal problem with a technological solution.
“The battle cry of these people have has always been—either directly or mocked as being—’Could somebody think of the children?’” Muffett said. “And I’m thinking about the children because I want my daughter to grow up with an untracked, secure private internet when she’s an adult. I want her to be able to have a private conversation. I want her to be able to browse sites without giving over any information or linking it to her identity.”
Muffett continued:
“I’m trying to protect that for her. I’d like to see more people grasping for that.”
Samsung has started selling the Galaxy Tab S6 Lite (2024) in the US. The new mid-range tablet is available on Amazon with a price tag of $329.99. The company seemingly hasn’t made it available on any other platform, not even its official website.
Galaxy Tab S6 Lite (2024) arrives in the US
After a series of leaks and rumors, Samsung officially launched the Galaxy Tab S6 Lite (2024) at the end of March. The company detailed its specs, most of which were already revealed by leaks, and shared the European prices. We subsequently got the tablet’s prices for the UK, but there was no word on its price and availability for the US.
However, as spotted by PhoneArena, the Galaxy Tab S6 Lite (2024) is now on sale in the US exclusively through Amazon. Samsung is offering the tablet in 64GB and 128GB storage variants, both with 4GB of RAM and SD card support. The 64GB variant costs $329.99, while the 128GB variant is priced at $399.99. The devices ship immediately and are available for free returns. Samsung has also bundled a $100 Amazon gift card.
Amazon is the only place you can buy this tablet from in the US. It is unclear why Samsung decided to make it exclusive to the platform. Nonetheless, if you plan to buy the Galaxy Tab S6 Lite (2024), we have provided links to both storage variants below. The links take you directly to product pages for the tablet on Amazon US. If you want to quickly check out the specs and features before buying, read on.
The Galaxy Tab S6 Lite (2024) is a refreshed version of a 2022 tablet of the same name, which itself is a refresh of a 2020 tablet. All three tablets have the same design and build quality. You get an aluminum body (including the back cover) and a 10.4-inch TFT LCD screen with a 1200 x 2000 pixels resolution. The tablet supports S Pen and Samsung DeX and comes with AKG-tuned stereo speakers.
Powered by Samsung’s Exynos 1280 chipset, the Galaxy Tab S6 Lite (2024) isn’t a powerful tablet but no slouch either. You get an 8MP rear camera with no flash and a 5MP selfie camera. The 7,040mAh battery is fairly big but a 15W charging speed is somewhat slow. Other highlights include Android 14, Wi-Fi 5, Bluetooth 5.3, and USB Type-C 2.0. While the tablet is available in a 4G/LTE version in other regions, Samsung seemingly didn’t bring it to the US. The device comes in Chiffon Pink, Mint, and Oxford Gray colors.
Recently, Nothing announced that they would be debuting two new earbuds on April 18. Well, how about we introduce you to the Nothing Ear and Nothing Ear (a) on April 8 instead?
First up is the Nothing Ear. These are going to be the more high-end version of the two earbuds, priced at €150. And the successor to the Nothing Ear (2), the company announced that they would be dropping the numbers from their naming for earbuds. These will include active noise cancellation, dual connection, and waterproofing with an IP54 rating, while the case gets an IPX2 rating.
Battery life is also going to be somewhat respectable here: 7.5 hours with ANC turned off, while the case will give you 33 hours. Nothing is also included, such as a fast charging feature, which allows you to get 10 hours of usage from just a 10-minute charge.
Nothing Ear will be available in black and white, as shown below. Nothing is sticking with the transparent look on these earbuds, which does look a bit more transparent on the white version. It is just a transparent stem, so the only difference in color is the earbud.
Nothing Ear (a) could be the best sub-€100 earbuds on the market
The Nothing Ear (a) is going to be pretty similar to the Nothing Ear, with the big differences being the waterproof rating and the battery life. So we’re still looking at dual connection, Active Noise Cancellation, and quick charging to get you 10 hours of playback in just 10 minutes.
On the battery life front, you’ll get eight hours of playback with ANC off, and the case will get you 38 hours of playback total. The buds are going to have a waterproof rating of IP54, while the case will get a IP55 rating. All of this for just €100.
With the Nothing Ear (a), the company will be releasing them in three colors – black, white, and yellow. The yellow color is meant to be more of an eco-friendly design for the Nothing Ear (a). But it’s unclear if the packaging will be eco-friendly, like being made from recycled paper and cardboard, just yet.
Meta and the FTC are currently in a legal fight over whether or not Meta acquiring WhatsApp and Instagram was a monopolistic move. The FTC claims that the practice was indeed monopolistic, but Meta is trying to dismiss this claim, reports Android Headlines.
Meta tries to get the Federal Court to dismiss the FTC’s antitrust lawsuit
In the ongoing legal battle, Meta claims that Instagram and WhatsApp’s acquisition was to the benefit of consumers. The company has now filed a motion for summary judgment in its lawsuit against the US FTC. Basically what it is is an attempt to get the court to dismiss the case. Meta claims the FTC doesn’t have evidence to support its claims. Meta insists that it didn’t become a monopoly after acquiring WhatsApp and Insta. Also, the social media giant highlights that it is facing fierce competition from a multitude of other platforms like TikTok, X, YouTube, and Snapchat.
The second point Meta makes is that its acquisition of WhatsApp and Instagram has benefited consumers. As the company claims, it has spent “billions of dollars” and invested “millions of hours” to make both these apps better, more reliable, and more secure.
Back in 2021, DC District Court Judge James Boasberg accepted Meta’s motion to dismiss the FTC’s complaint, but the judge did give the FTC a chance to file an amended complaint which was then allowed to proceed.
Meta claims that in the FTC complaint, the market definitions are “unreasonably narrow”. It seems like the FTC has excluded platforms like TikTok and YouTube from the market it is focusing on. The market instead only includes Facebook, Insta, Snapchat, and MeWe, claims Meta.
It is now FTC’s turn to respond. As with any legal battle of the sort, these back-and-forth court filings may continue for months before a resolution is found.
Izzy, a tech enthusiast and a key part of the PhoneArena team, specializes in delivering the latest mobile tech news and finding the best tech deals. Her interests extend to cybersecurity, phone design innovations, and camera capabilities. Outside her professional life, Izzy, a literature master’s degree holder, enjoys reading, painting, and learning languages. She’s also a personal growth advocate, believing in the power of experience and gratitude. Whether it’s walking her Chihuahua or singing her heart out, Izzy embraces life with passion and curiosity.
Cisco recently fixed a high-severity vulnerability in Cisco IOS Software for Catalyst 6000 Series Switches, which could lead to a denial of service (DoS).
This high-severity vulnerability, which has a base score of 7.4 and is tracked as CVE-2024-20276, is triggered by improper handling of process-switched traffic.
Cisco IOS (Internetwork Operating System) is a set of proprietary operating systems (OSes) that run on Cisco Systems hardware, such as routers, switches, and other network devices.
Cisco IOS comprises essential functionalities such as interface configuration, network management and monitoring, routing, security, switching, and quality of service (QoS).
Details Of The Cisco IOS Vulnerability
This Cisco IOS Software flaw for Cisco Catalyst 6000 Series switches could allow an unauthenticated, local attacker to force an unexpected reload on a vulnerable device.
The vulnerability stems from the improper handling of process-switched traffic.
An attacker may take advantage of this flaw by directing malicious traffic to a vulnerable device.
If the exploit is effective, the attacker could trigger a denial of service (DoS) issue by forcing the compromised device to reload.
“An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition”, Cisco said in its advisory.
Affected Products
Suppose any of the following Cisco products are running a vulnerable version of the Cisco IOS software and have activated port security, device classifier, or authentication, authorization, and accounting (AAA). In that case, they are susceptible to this vulnerability:
Catalyst 6500 Series Switches with Supervisor Engine 2T or 6T
Catalyst 6800 Series Switches with Supervisor Engine 2T or 6T
Use the show running-config | include interface|port-security command to find out if a device has port security setup.
This vulnerability affects a device if port security is enabled on an interface.
Use the show running-config | include device classifier command to see if a device has device classifier configured.
The device is susceptible to this vulnerability if the command returns output.
Use the show running-config | include system-auth-control|interface|port-control|mab command to find out if a device is configured with AAA.
This vulnerability affects a device if AAA is enabled on the interface.
Products Not Vulnerable
The following Cisco products are unaffected by this issue, according to Cisco
IOS XE Software
IOS XR Software
Meraki products
NX-OS Software
Cisco has verified that the following Cisco IOS platforms are unaffected by this vulnerability:
Catalyst 1000 Series Switches
Catalyst 2000 Series Switches
Catalyst 3000 Series Switches
Catalyst 4000 Series Switches
Catalyst 9000 Series Switches
There are no workarounds to address this vulnerability. Users are encouraged to upgrade to the appropriate fixed software release to mitigate the risk posed by this vulnerability.
Cisco has made these updates free for customers with service contracts, accessible through their usual update channels.
For customers without service contracts, upgrades can be obtained by contacting the Cisco Technical Assistance Center (TAC), with the product serial number and the URL of the advisory as evidence of entitlement to a free upgrade.
Secure your emails in a heartbeat! Take Trustifi free 30-second assessment and get matched with your ideal email security vendor - Try Here
Right now, we’re getting a tidal wave of new information surrounding Samsung’s upcoming Z Fold smartphone. While we expect these phones to be an improvement over last year’s model in several ways, it appears that one area of the phone will not see any change. According to reports, the Galaxy Z Fold 6 may have the same camera setup as last year’s foldable phone.
One area where Samsung’s Galaxy foldables haven’t been impressing audiences is the camera. These phones usually fall behind in the camera department, and this is something that people have commented on ever since the beginning. The cameras are never bad overall, but they’re always underpowered compared to the latest Galaxy S phone.
The main thing that annoyed people was the fact that the Galaxy foldable phones are so expensive compared to other flagship phones. So, it just feels weird having underperforming cameras on a nearly $2,000 phone.
The Galaxy Z Fold 6 might have the same cameras from last year’s foldable phone
Even though this news is coming from a notable leaker, you’ll still want to take this news cautiously. We’re not dealing with official information, and there’s always a chance that new information could arise before the official launch.
According to notable leaker Ice Universe, Samsung may fit the Galaxy Z Fold 6 with the same camera package present in the Galaxy Z Fold 5. It notes that everything could be the same from the main camera to the under-display camera.
Last year’s Galaxy Z Fold 5 (Review) had a 50-megapixel main camera sensor with an F/1.8 aperture, 10-megapixel 3x telephoto camera with an f/2.4 aperture, 12-megapixel ultrawide camera with an f/2.2 aperture, 10-megapixel external selfie camera with an f/2.2 aperture, and 4-megapixel under-display camera with an F/1.8 aperture.
The cameras on this phone were good, but they weren’t befitting of the high price tag. Well, it appears that the Galaxy Z Fold 6 will mirror these camera specs and be yet another step behind the top flagships of the year.
Better camera specs might come, but they could cost you
Along with rumors of the Galaxy Z Fold 6 coming, we’ve also been following rumors surrounding the Galaxy Z Fold 6 Ultra model. As the name suggests, it will be more powerful and more expensive than the standard Galaxy Z Fold 6 model. News about this Ultra model is still very scarce, so we don’t have much to go on. However, it’s possible that Samsung could fit better camera specs into the Ultra model and leave the standard model with last year’s specs.
We will have to wait for more information on that model.
Google and Nest are two brands that are commonly associated with the modern smart home market. Despite both companies being involved in the smart home industry, they are not the same brand. This article aims to provide a detailed explanation of Nest and its products, as well as answer some of the most frequently asked questions about them. It will also provide tips on how to maximize the use of Nest products that you already own.
What’s the difference between Nest and Google?
Summarily, Nest is a smart home-specific company operating under the more familiar brand Google LLC, which serves as its parent company. Of course, Google LLC is under the parent company Alphabet, But it started out on its own footing.
Prior to merging fully with Google in 2018, Nest had its own endeavors. That began with the AI-powered Nest Learning Thermostat in 2011 and was followed up by carbon monoxide and smoke detectors in 2013. Those were all under the “Nest Protect” branding. The company acquired Dropcam and Revolv in 2014. While it adopted Dropcam products into its own lineup, it effectively shelved Revolv products.
Also, prior to fully merging with Google, the company took its Nest Learning Thermostat to its 3rd Generation in 2015. And released a subsequent follow-up with the Nest Thermostat E in 2017. A new Nest Protect-branded smoke alarm and carbon monoxide detector launched in 2015 as well as the original Nest Cam. That was followed by the Nest Cam Outdoor in 2016 and the updated Nest Cam IQ in 2017.
Under Google, those devices were followed by various smart home gadgets, from the latest Nest Thermostat to the Nest Cam and Doorbell (Battery).
Now, Google and Nest are effectively the same company, with Nest operating as a subsidiary. So the biggest difference between Nest and Google is that some older Nest products connect to both the Nest app and Google Home app for smart home integration while the latest cameras only require the Google Home app and don’t appear in the Nest app.
Nest, of course, is also responsible for the Nest Aware service. That’s a value-added service for all Nest-branded products. It adds features such as noise detection for smoke alarms and breaking glass. It also increases the amount of time and which events are recorded and stored. But we’ll dive into that a bit later on in this explainer.
What are the current Nest products?
Now, Nest products have been released steadily since the company’s founding. But the current run of products is quite a bit more extensive than where Nest started. Especially since Google has begun to place all of its smart home products under the Nest brand. This means that there are now no fewer than ten categories for its products if you navigate over to the Google Store page.
For instance, for smart home entertainment, Nest now has the Speakers and Streaming categories. The latter of which houses the Google-branded Chromecast and Chromecast with Google TV. While the former category houses its Nest Mini (2nd Gen) speaker and Nest Audio speakers.
What’s more, the apparent trend of featuring two products in those categories continues across the remaining categories. So, for example, in Display-centric smart home hubs, Nest has its smaller Nest Hub (2nd gen) and its full-size Nest Hub Max. Under doorbells, it has a new wired and wireless version of its doorbell. And that holds for its cameras as well. Although it also still sells a combination floodlight and camera package.
There are additionally two home thermostats — including an older “Learning” thermostat and a newer model. It will also provide a temperature sensor to help HVAC systems better handle managing multi-level homes.
All of which is to set aside the company’s two mesh internet offerings and a plethora of accessories for powering, protecting, or repositioning the products. And, of course, without consideration for partnered products such as the Nest x Yale Lock.
Conversely, the company also sells Nest Protect smoke & CO alarms, installation services, and consultation services.
Finally, Nest does have a couple of Mesh WiFi Systems available, there’s Nest WiFi and Nest WiFi Pro. The main difference between the two is WiFi 6E being available on the “pro” model.
Of course, all of these products are available for control through the Google Home app on web, Android and iOS. Making it easier than ever to control everything in your home.
Do Nest cameras record all of the time, and how do you know?
Whether Nest cameras record all of the time depends entirely on the subscription level chosen and on the camera that’s been selected. The newest, battery-powered cameras cannot record all of the time. Even when wired up to a secondary source to charge the battery — effectively making them ‘wired’. They can be viewed live at any time and record events. But they cannot record 24/7 video feeds.
Older cameras can and do record all of the time when a Nest Aware Plus subscription is in place. With up to 10 days of recordings saved, as we’ll discuss in the next segment here.
Equally importantly, all Nest cameras indicate on-device when they are recording. Namely, via the built-in LED lights. Solid green lights on the cameras themselves indicate that a recording is being made. So, for example, when a camera is recording at all times via a Nest Aware Plus subscription, the light stays on. Or when an event is being recorded.
A blinking light, conversely, indicates that users with access to the cameras are watching. The light comes on anytime the live video is being viewed.
Do you need to pay for Nest?
One important fact to note about Nest products is, in fact, that they don’t typically come with added after-costs; namely, subscriptions.
Nest does have a Nest Aware subscription available. However, for most Nest products, simply paying for the product will give you its full range of functionality. Or very close to it. For instance, if only Nest speakers, Chromecast, or WiFi gadgets are in use, there’s no benefit to a subscription service. The same can be said of Thermostat products.
For the Nest Hub-branded smart displays, improvements are available if the video recording features are turned on. For facial recognition, keeping track of “seen” faces and activity zones. Or if you’d like your Nest Hub to recognize sounds like a smoke alarm or glass breaking — or more intelligent motion tracking since basic tracking is included out of the box.
The full range of benefits for cameras is similar to those available with the Nest Hub Max, which is camera-enabled, for instance. With added benefits for recording and storing footage, too. For instance, Nest Aware Plus gets users 10 days of continuous 24/7 video history. And 60 days of event history. They’d just have 30 days of event history with Nest Aware and either 5, 10, or 30-day continuous video history with the original, 1st-Gen Nest Aware subscription.
That, in turn, feeds into other advanced features that wouldn’t otherwise be available, such as saving and sharing video clips. But a subscription is absolutely not going to be necessary for most buyers, especially with e911 services included for both subscription levels. And, even then, it isn’t overly expensive. Starting at just $6 per month for Nest Aware or $12 per month for Nest Aware Plus. With a 30-day trial available for those who are just getting started.
How do you use Google Nest products & do you need to use the Nest app?
Now, as far as access, features, and functionality, some Nest products do require users to access them via the Nest app. Around half of them, in fact.
For instance, the latest Nest Thermostats, smoke alarms, door locks, temperature sensors, and services such as Nest Aware and installation. Older camera models, excluding the latest “(Battery)”-designated models, require the app too.
Speakers, the newest cameras and doorbells, the mesh Wi-Fi gadgetry, and even the smart home hub displays all use Google Home instead. As do Google Chromecast and Chromecast With Google TV. However, for those latter two products, the app is mostly just for setup.
So the biggest difference between Nest and Google is that some older Nest products connect to both the Nest app and Google Home app for smart home integration. But others simply use the Google Home app. And future products will likely continue that trend.
That’s made using Nest products less intuitive than some might have hoped. But, fortunately, we have an extensive list of how-to guides to help get started with some of the interactions users will access most commonly.
Artificial intelligence is becoming a bigger and bigger part of our online and mobile world, and it is happening pretty fast. One popular feature powered by generative AI is summarization, which lets users get quick summaries of articles, docs, and even phone calls. Now, it seems Google is gearing up to introduce email summarization in the Gmail app.According to PiunikaWeb, teaming up with AssembleDebug, Gmail on Android might be in for a smart upgrade that will give you the scoop on lengthy emails using AI, saving you the hassle of sifting through all the details. In version 2024.03.31.621006929 of the Gmail app, they spotted a new button called “Summarize this email.”
Just so you know, Google already offers email summaries for users of its Gemini for Workspace suite, but it is currently only available in the web version of Gmail. So, it is not exactly shocking that it is now heading to the Android app. This new feature could be quite handy for Gmail on smartphones, especially for those long emails or ones jam-packed with info.Plus, this new button on the mobile app looks like it might be for everyone, not just Workspace suite users. As seen in the screenshot above, the button pops up right under the subject line. But since the feature is still in its early testing phase, tapping the button doesn’t do anything yet.
It is likely that tapping it will bring up a little pop-up window at the bottom of the screen with a summary of the email in bullet points. Kinda like how it works on the web, but instead of the side panel, we’d get this handy pop-up.
In addition to the “Summarize this email” button, the tipster also noticed a Gemini entry in the three-dots menu on the top bar. Right now, it doesn’t do anything – it just opens up a blank sheet with the Gemini logo and some text.
Google’s Gemini is LLM (Large Language Model). It is trained on large amounts of publicly available data and can communicate and generate human-like text in response to a wide range of questions.
By exploiting the AI tools deepfake hackers could make videos or audios of political candidates to spread misinformation or disinformation, which may be used in election campaigns.
Large language models (LLMs) can also enable them to produce realistic but misleading content at scale, thereby exacerbating division and fake news on social media.
Recently, cybersecurity analysts at Microsoft discovered that Chinese hackers are actively exploiting AI tools to influence the upcoming elections.
State-sponsored actors leverage evolving tactics to advance geopolitical agendas. Beijing employs fake social media accounts and AI-generated content to sow discord and influence U.S. elections.
Besides this, North Korea has increased the pace of cryptocurrency theft and supply chain attacks with AI to fund military expansion.
DocumentStop Advanced Phishing Attack With AI
Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Stopping 99% of phishing attacks missed by
other email security solutions. .
The most recent Microsoft East Asia threat report highlights these facts as further evidence that nation-state threats are ever-evolving.
The coordinated Chinese campaign on social media to influence the U.S. elections is going, with fake accounts pretending to be voters and making louder content about climate change, immigration, and race via original as well as recycled posts.
Chinese sockpuppets solicit opinions on political topics (Source – Microsoft)
In recent times, “polling” has been employed to establish voter opinion on controversial matters that could allow for customization of information operations during peak seasons associated with the presidential election cycle.
China’s IO in the US exploited events to serve strategic interests by casting a bad light on America.
They alleged that the U.S. intentionally started Maui wildfires, insinuated that the U.S. may have caused a Kentucky train derailment, and accused the U.S. of water poisoning for power sustenance.
Such methods also included calling into question Japan’s wastewater disposal system as part of efforts to undermine IAEA findings.
AI-Generated Memes (Source – Microsoft)
The 2024 Taiwanese presidential election marked the first known instance of AI-generated content being used in foreign influence operations by China-affiliated Storm-1376.
Videos published by Storm-1376 used AI-generated voice recordings of Terry Gou (Source – Microsoft)
They uploaded what appeared to be computer-generated audio of former candidate Terry Gou supporting someone else, which was quickly removed from YouTube.
The first-ever country that has employed AI in interfering with elections seems to be China.
Storm-1376 increased AI-generated memes mocking Taiwanese officials and dissidents, including AI news anchors, since early 2023.
North Korea prioritized crypto theft and supply chain attacks against adversaries to fund weapons, stealing over $3 billion since 2017, $600 million-$1 billion in 2023 alone.
Timeline of AI influence in Taiwan election (Source – Microsoft)
Used AI tools by Emerald Sleet group to enhance operations against the U.S.-Japan-South Korea alliance before Microsoft and OpenAI disrupted their activities.
Major elections in 2024 risk China amplifying AI-generated content to serve its interests, though the impact remains limited for now.
However, China’s AI meme/video/audio augmentation experiments persist.
Expect North Korea’s crypto heists and supply chain attacks on the defense sector to fund weapons programs.
Secure your emails in a heartbeat! Take Trustifi free 30-second assessment and get matched with your ideal email security vendor - Try Here
This article was authored and contributed by Keir Finlow-Bates, a passionate blockchain enthusiast and technologist.
Today over at Resonance Security I am going to look at one of the more unusual ways in which your approach to computer security can lead to an increase in public awareness of your company.
There are many motivations for starting a company: becoming wealthy, doing something interesting and useful, and leaving some kind of legacy or mark on history are three of the main ones that spring to mind.
About that legacy: imagine having the name of your corporation attached to a file representing one of the most significant hacks of the 21st century!
That’s quite notable, but probably not what the founders of one particular company were looking for with their startup.
We won’t rock you
In the middle of the 2000s, RockYou, Inc. was doing well as a widget-maker for social media companies like MySpace and Facebook. However, back in 2009, it suffered a data breach in which a hacker discovered an SQL database server with an unpatched ten-year-old bug, the database containing over 32 million usernames and passwords for user accounts.
That’s right — 32 million usernames, and their associated passwords. For comparison, that’s about 10% of the active monthly users that Facebook had at the time.
The passwords were stored in plain text.
Mud on your face, big disgrace
Not only did RockYou initially fail to notify their users, but it subsequently released a falsified official statement claiming that the breach was less severe than it was.
To be clear: it was a very, very serious breach.
A decade and a half ago, people were far worse at password security than they are now. Password managers were almost unheard of, for some unexplained bizarre reason some sites blocked the use of password managers for unspecified “security reasons”, and two-factor authentication was pretty much only affordable and available to business users.
Because people were told not to write down their passwords, this meant that most of the leaked credentials were being used on other websites. After all, who in their right mind is going to memorize twenty or thirty different random passwords? As a result, sites such as banks, online stores, health databases, social media, supposedly private online journals, and online games held accounts using the same passwords.
The legacy
For years the full list of RockYou passwords has been available to download by anyone. It is typically found in a file called rockyou.txt , and there are plenty of GitHub repositories out there where you can find it.
In Kali Linux, a Linux distribution designed and produced specifically for penetration testing, the RockYou text file is included during the installation by default.
Conclusion
Just imagine — with a little bit of security carelessness, you too can take your modestly successful company and in the process of destroying it, allow its name to live on forever.
Have we learned anything since 2009? Not always.
For example: in 2017 it was revealed that an old social media site called LiveJournal, dating back to the 90s (but still running to this day), suffered a breach in which 26 million unique usernames, email addresses, and plaintext passwords were extracted. It took them until 2019 to admit to the breach.
That’s right — passwords were still being stored in plaintext in 2017, and I would bet good money on there being more sites out are doing the same, even though we are a decade and a half on from the original RockYou breach.
I predict that the leakage of passwords will only end once we stop using passwords, and start using improved systems such as security keys and self-managed identity for our authentication systems.
In the meantime, you have to assume that any password you provide to a website will eventually be leaked, therefore:
use a password manager to generate long, random, unique passwords for your accounts,
protect access to the password manager with two-factor authentication, and
make sure the password you use for your password manager has never been used anywhere else.
Post-script
Don’t run off and look for a website that allows you to enter your password and see if it was ever revealed in a breach! I can guarantee it will be a phishing site. Instead, I recommend HaveIBeenPwned, where you can type in your email address, and retrieve a list of the companies and websites that have managed to leak your credentials to the dark web through bad security practices. Another option is the Resonance Data Leak Detector, which monitors if your credentials have been leaked 24/7 and automatically notifies you.
About Resonance Security
Resonance Security is a curated platform for end-to-end cybersecurity products and services. It functions as a concierge for your organization’s end-to-end cyber-security needs, aggregating valuable security offerings into one platform to spread awareness on what it takes to secure your technology stack end-to-end.
About the author
I’m Keir Finlow-Bates, often known as Blockchain Gandalf, and am primarily a blockchain researcher and inventor. I started on this journey in late 2010 by examining the original Bitcoin code, and have been obsessed with blockchain ever since.