Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Interesting, my account's Security History shows a few failed login attempts in the last 3 days from Eastern Europe and Southeast Asia, and my account is not even popular.


I had 13 login attempts from South America, Asia and Middle East. My login details have been leaked in several leaks, latest being the Adobe leak. And even though I've had strong password, my fault's been that I've used the same password in lots of places.

Luckily the Adobe leak was the final straw and I finally started to use a good password manager and super strong, distinct passwords in all the services I'm using. It wasn't that bad at all, just selecting a good password manager[1], strong encryption and an easy way to sync your passwords between devices (git), I've had no trouble at all with strong passwords.

Although it would be nice to have an Android app for the password manager. I think it's a nice excersize for writing my first Android app at some point...

[1] http://zx2c4.com/projects/password-store/


I use Keepass, which has an Android client. Sync is via Dropbox, soon (I hope) to shift to git-annex.


Your comment prodded me to check my own Security History, and I have five failed login attempts within the past 3 days from unrecognized IPs also on a not-popular account.


I do as well. One from Korea and one from Venezuela.


I have 12 failed attempts in the past 4 days, and I don't have a popular account either.


Yep -- in my case from Turkey, France and Venezuela. And I'm in California.


Same here, from Venezuela and Turkey. My github isn't affiliated with any company, so I don't really see the point in trying to hack into it.


A friend and I both showed 6 login attempts from unique IPs and neither one of us are very active. Seems like they hit a lot of people.


I've seen a small amount of suspicious activity (possibly 3 failed logins that weren't mine); I'm wondering how relevant various attributes of the username are. I'm starting to move to unique usernames for various services: not anything vastly secure, but something that's at least harder to automatically cross-reference. Does anyone know if using much longer usernames is a worthwhile investment?


They did the OAuth token with the Ripple give away 16 days ago, and before that, I had no failed attempts, just a single successful attempt. I too used the same password for a few sites.


India here. Don't underestimate the long tail of user distribution.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: