Hacker News new | ask | show | jobs
by tptacek 6394 days ago
Few months ago, someone I know (nontechnical) lost their password on a public blog server. Unfortunately, like most people, they used the same password on their Yahoo mail account. Inside of a day, they:

* Got locked out of their Yahoo mail account for a week

* Lost their GoDaddy account, got locked out of it, and had it redirected to a gay porn site

* Lost their bank account, had thousands in fraudulent charges racked up, and got locked out of the account

* Had all their Yahoo mailing lists scrubbed, and each mailing list member (including his kids soccer team, which he ran) spammed with gay porn stuff

* Had his tax dox and personal mail dumped in public.

It sounds like your Google experience sucked. But I can think of worse things that can happen than a beaurocratic SNAFU. Let's not just hope that people will get smart about their passwords.

1 comments

Wasn't this a targeted attack against a security blogger?
Yes. Under normal circumstances, the attackers would have silently harvested all the victim's accounts and sold them in Estonia.