submitted 2 years ago* (last edited 2 years ago) by to c/technology@lemmy.world
 

I just got the email from haveibeenpwned. F Trello.

top 50 comments

sorted by: hot top controversial new old
[–] 165 points 2 years ago (36 children)

Obligatory: companies should face harsh penalties for this stuff.

  • source
  • hideshow 36 child comments
  • [–] 50 points 2 years ago (2 children)

    They do, in the EU. If you fuck up your customer's data, you'll face fines consisting of hefty percentages of your yearly revenue!

  • source
  • parent
  • hideshow 2 child comments
  • [–] 38 points 2 years ago* (8 children)

    This is not something a company did.

    The group of people took a list of user names and passwords from a different breach and tried them on trello to see if people used the same password and wrote down which ones did.

    Nothing a company can possibly do to stop this, only users can.

    Even if the company required 2 factor authentication to fully log in, getting this far would still confirm each account/password combo was correct, which is all the "hackers" did.

  • source
  • parent
  • hideshow 8 child comments
  • [–] 21 points 2 years ago (5 children)

    This isn't completely true, but it is the current standard.

    A website can detect and block many user/password attempts from the same IP and block IPs that are suspicious.

    Websites can detect elivated login fails across many IPs are react accordingly (It may be reasonable to block all logins for a time if they detect an attack like this)

    I'm sure there are other strategies, I don't know how often they are actually employed, but I wish companies would start taking this sort of attack more seriously (even if it's not at all hacking)

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (2 replies)
  • load more comments (1 reply)
  • [–] 26 points 2 years ago (12 children)

    Yes but this wasn't a data breach. This was a data stuffing incident, meaning they took someone else's data dump and tried their email and credentials here.

    • never use the same username and password in two or more places
    • always use MFA, a hard token if you can like a yubikey
  • source
  • parent
  • hideshow 12 child comments
  • load more comments (9 replies)
  • [–] 12 points 2 years ago (6 children)

    I agree that data security is important, even if it is only email addresses, where many are probably findable in the web anyway. Maybe, the link with the username has some value, but I’d bet only little. In my opinion, harsh penalties are more needed in privacy invasive (in my opinion malware) like google, meta, Amazon etc. are spreading.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 9 points 2 years ago (5 children)

    The problem is that this data can be combined with other data. An email address by itself isn't particularly important but when it's matched up with names, physical addresses, DoB, SSN, other PII and the network of other services with matching data it becomes very serious.

    It's never just this breach, it's every other breach as well. Every breach makes every preceeding breach more effective and more valuable.

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (5 replies)
  • [–] 53 points 2 years ago (3 children)

    Literally never heard of Trello in my life until today...when my boss sent me a link to join their board...

  • source
  • hideshow 3 child comments
  • [–] 49 points 2 years ago (15 children)

    My email has been leaked 20 times now, how lovely

  • source
  • hideshow 15 child comments
  • [–] 34 points 2 years ago* (14 children)
  • [–] 11 points 2 years ago (5 children)

    I exclusively use alias emails and have found the down side. If you use an alias email for each site you visit (let’s say an online shop that is ran by Shopify) there is an extremely high chance your purchase will be flagged (fuck you Shopify) as a fraudulent account. I am constantly being flagged on sites with Shopify back ends for fraud. It really sucks when your hoppy (FPV Drones) is mainly ran by Shopify sites.

    P.S. There is no one to help resolve these issues with Shopify as they don’t have a customer support unless you’re a customer and the store owners are either dumb on how to help or just plain lazy.

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (5 replies)
  • load more comments (3 replies)
  • [–] 39 points 2 years ago (3 children)

    "Breached" implies that sensitive data, like payment details, private communication, or physical addresses, were leaked. Instead, this is just semi-public stuff like email/username/name. Maybe a better title would be "15M Trello users have been identified (name/email)"

  • source
  • hideshow 3 child comments
  • [–] [S] 27 points 2 years ago* (2 children)

    Of course. But are you sure “identified” is correct word here? I chose “breached” because title of mail was “You're one of 15,111,945 people pwned in the Trello data breach”

  • source
  • parent
  • hideshow 2 child comments
  • [–] 29 points 2 years ago (4 children)

    That's not what it means to breach an account...

  • source
  • hideshow 4 child comments
  • [–] 28 points 2 years ago (1 child)

    Funny. Back in my l337 days public Trello boards were one of the easy ways to get passwords. People would put shared passwords for team accounts just on their board, in plain text

  • source
  • hideshow 1 child comment
  • [–] 24 points 2 years ago (1 child)

    Hey OP, I'm doing some research. You mind sharing that link in the description of your screenshot?

  • source
  • hideshow 1 child comment
  • [–] 20 points 2 years ago (2 children)

    15M Trello accounts have been leaked

    That title is very misleading. 15M Trello accounts were found to be compromised because of other, previous leaks, but no leak related to Trello occurred.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 18 points 2 years ago (8 children)

    Why isn't Trello / Atlassian warning about this?

  • source
  • hideshow 8 child comments
  • load more comments (1 reply)
    [–] 16 points 2 years ago (4 children)

    Dumb question time

    What is Trello?

  • source
  • hideshow 4 child comments
  • [–] 23 points 2 years ago (3 children)

    It's a kanban board that atlassian a popular company that makes apps for developers bought out.

    Not sure if you used a kanban board before but basically you put items that need to be done in columns with typical headers (can be changed) of "to do, doing, blocked, done". So that one can keep track of work/goals etc.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 9 points 2 years ago (2 children)

    I definitely have not used a kanban board. It seems I am far less involved in the technical world than most Lemmy users

  • source
  • parent
  • hideshow 2 child comments
  • [–] 14 points 2 years ago

    No unauthorised access has occurred

  • source
  • [–] 11 points 2 years ago (2 children)

    Nobody watches sever logs 😞

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [+] 11 points 2 years ago (4 children)
  • [–] 32 points 2 years ago (3 children)

    Because you think they delete your data?

  • source
  • parent
  • hideshow 3 child comments
  • [–] 11 points 2 years ago

    Wait til these people hear about phone books

  • source
  • load more comments
    view more: next ›