Back to Writing

711 million of us have been PWNED!! But DON'T PANIC!

A breach-notification note about password hygiene, Have I Been Pwned, and responding calmly to alarming security news.

Original LinkedIn version

Last night at 10:45pm UK time my phone flashed with an email. Nothing out of the ordinary really. Except that this time it was from haveibeenpwned.com which I’ve found to be really useful in the past for letting me know about my details being potentially compromised and shared.

This particular email concerned a “massive 711 million leaked records” containing email addresses and passwords. That’s one for almost every citizen of Europe (at time of writing 743 million(ish)). That’s a LOT of leaked records but still nowhere near the Yahoo data dump from last year.

This was concerning, and like most users of haveibeenpwned.com I rushed online to find out more information about this and went through their informative explainer.

The writer went through the data, combing through lines of code and cross-checking against other known sources. Apparently this dump came from a “spam list”. Fortunately and unfortunately this spam list seems to have been compiled from several earlier breaches including the LinkedIn leak in 2012. The fortunate part of this is that chances are good that nothing additional has been leaked and shared which could compromise your security further. The unfortunate piece comes from the fact that without being able to identify the source, users won’t know for definite that this is the case, which passwords to change or which accounts to shore up to protect themselves from being further exploited.

Reading through the accompanying article helped to set my mind at rest that my email was in this purely as a result of the original LinkedIn email dump with my passwords having changed several times since then (at least 3 times this year so far) rendering any potential password linked to that account useless to a would be cyber-criminal, but not to spammers.

So what should everyone do with this new information?

The same thing they should be doing regularly.

Audit your passwords.

Make sure that you are using secure passwords.

Whether you’re using long, concatenated strings, password manager applications or any other method of strengthening your password, make sure they’re secure and different for every account you use.

If you’re wanting to stay ahead of the curve with password security I highly recommend reading some of Prof Bill Buchanan’s articles on LinkedIn. Some of the content will go over the heads of everyday users, but in general there is a lot of pertinent advice about passwords and data security.

So don’t worry too much about the haveibeenpwned email which might be sitting in your inbox. Use it as a gentle reminder to audit your passwords and take your online security seriously. There will be attention grabbing, doom-mongering, the-end-is-nigh articles about this. Just remember what Douglas Adams informed us was printed on the cover of the Hitchiker’s Guide to the Galaxy in nice, bold, friendly lettering: Don’t Panic!