So you may or may not be aware of the Gwaker Media hack and theft of passwords this week but basically Gwaker's websites were hacked and the user logins (email addresses) and passwords were taken.
Gwaker says the file containing the passwords is encrypted but it seems from the messaging that Gwaker is promoting that they feel it is a matter of time until the passwords are compromised.
Gwaker Media includes the following sites:
Lifehacker, Gizmodo, Gawker, Jezebel, io9, Jalopnik, Kotaku, Deadspin, and Fleshbot
Unfortunately even the best of us got hit by this one and goes to show there isn't a thing you can do about it! I love Lifehacker and Gizmodo and knowing I have accounts there, I checked on my email to see if it was in the list. It was.
Oddly enough I got an email from Hint.io the other day regarding this but disregarded it as SPAM turns out that according to Lifehacker Hint.io is trying to be "digital good samaritans", emailing users at addresses included in the leaked database to warn them of the leak. The links in their email were questionable so I didn't bother clicking on them to stay safe and we recommend staying cautious just in case.
Luckily, I use a "throw away" password for many of the generic sites that I log into BUT the down side is that I use the same password at all of these sites and more. Since many of them use my email as the login, these hackers now have access to all of the other sites that I sign up for!
I still think that having a three password approach is adequate for my needs though:
- One that only I know for my business, banking, investments, and such.
- Another that I use for semi-secure items (e.g. personal email, facebook, etc)
- And finally a password that I really don't care about for sites that I really don't care if someone gets into.
Regardless, I'll likely pick out a new throw away password and get to changing them on all the sites that I can remember! My concern isn't that someone gets into my accounts but that they start posting information as me on these sites! In today's connected world it is more a matter of reputation than information!
BTW here are some links to details as well as the tool I used to look up my account!
Tool to see if you got "Gawkered": http://www.didigetgawkered.com/
Lifehacker FAQ regarding details on the breach: http://lifehacker.com/5712785/#2
- Steve