Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's hard to detect credential stuffing. If people reuse passwords[1] they are going to have a bad time. Maybe they could have automatically locked accounts that appear in compromises, and while they should do that, I wouldn't go so far as saying they must do that.

Maybe they could have detected the exfiltration, but maybe they couldn't. If the hackers were smart they would have properly distributed the calls and rate limited to avoid detection.

>effective access to 6.9 million accounts

The relatives feature lets you -- if you opt in -- see your DNA relatives and their very basic details, and vice versa. I have literal thousands listed, and those thousands, all over the globe and of mostly minuscule relations, can see mine. That really is being a bit overwrought as a facet of this.



There are lots of ways to mitigate against credential stuffing. There are methods to detect botnets accessing your system at scale. There are products like HIBP that can help prevent credential re-use. You can prevent logins from unusual locations with an additional factor ("it looks like you're accessing this website from Croatia when you've only ever logged in from California, check your email for a confirmation code"). You can force MFA if you want to go nuclear.


What is [1] referencing?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: