Thursday, September 11, 2014

Catastrophe: stolen passwords from mail Yandex, Mail.ru and Google! – TVNZ

Oh, before something like a good idea: “You have sold Slavic closet?” And try to find the right comment on this stupid question! Without the Gestapo will not manage. And now …

All week online world was shaking. It’s no joke:

5 September was posted on the web database passwords to mailboxes Yandex – 1260614 addresses!

September 8th – the same thing happened to Mail.ru – 4425522

10th – new wave, already about Gmail.com – 4,661,763 pieces. Moreover, not only Russians, but also people from other countries.

Experts say about 60 percent of the actual password. Although it is likely, from the mailboxes that have not enjoyed. Who collected these bases? And why merged them into the network?

Question – why steal passwords – is not: it is clear. It is not to read as Pasha fools letters head Masha. Now e-mail passwords, as a rule, also the key to access to various Internet services, to the bases of personal data and other important information and money.

Well, for example, on the portal of public services, you can only go at e-mail address and password. Many recorded the same password, which is needed in order to enter into the very conversation. On this portal you about has it all – location, size of the apartment, number of the car, rent arrears and penalties, write to the queue in kindergarten. In general, take it and enjoy it.

In the same way can be used, and the resulting unjust by access to internet services. Example: Android smartphone to access the machine is possible with the introduction of account Google. And then all your purchases and expense.

So knowing your e-mail password, consider it access to your personal world.

But such information hackers usually kept secret – they are the same on it is necessary to make. And then – it was thrown in the open access.

Representatives of Yandex, Mail.ru and Google in one voice say: they are not to blame.

«We do not confirm the fact of the leak. Our experts understand what really happened, “- says a Google spokesperson Svetlana Anurova.

– Most likely, passwords have become known due to the fact that the computer users worked malevolent software. It aired information attackers – explains the deputy head of the department operating Yandex Vladimir Ivanov.

A simple example: you go to the site and you are asked to confirm whether you are this, enter your email address and password. Your passwords are stored in databases and online stores. There are viruses and Trojans that creep into your computer when you open an attachment sent from unknown addresses (and, sometimes more often, as with the well-known). Such a virus is quiet, only spying on you and sending to the right address your personal data when you get in the mail or use internet banking.

– I think there was not a conspiracy against one or more computer companies – confirms and vice president of Mail.Ru Group Anna Artamonov. – Most likely a result of the “work” of different hackers and they were extracted by different methods (phishing, viruses, hacking databases).

– Why for no reason at all for one week declassified just three database?

– It is not clear what purpose logins and passwords to “merge” right now, – says Vladimir Ivanov. – The base is almost “empty”, users who still use these passwords is not enough. So they are no longer of value to attackers. Moreover, most of the compromised accounts we knew for a long time, and sent to their owners request to change your password. This means that such base going for several years. In fact it is a single base. Only her publish disaggregated by domain.

– How does the system protect your mailbox. For example, your Yandex?

– We have several levels of security. Firstly, it is we have the technology to protect user data that is stored in the data center. Secondly, we encrypt outgoing and incoming mail. Third, there is a technology user authentication and authorization stage during his work with the mail. We have a system to get rid of malicious attachments in emails, check attachments for viruses. “Leakage” passwords and correspondence of the human factor also excluded: data on logins, letters, which belong to them, and the very content of the letters are stored in three different locations, for which there are three different groups of system administrators.

WHAT TO DO?

It is understood without e-mail can not do. Practice good hygiene. You wash your hands before eating? Here and in the electronic world try not to pick up a virus. And for this, according to the expert, “Kaspersky Lab” Yuri Namestnikova need:

– carefully check the address of the sender, if you received a letter from the administrator of any service;

– do not click on links messages from unknown recipients;

– authenticate the address bar of your browser when you enter personal data, and best of all – use a secure connection https;

– Only use complex passwords are different for different accounts and services;

– two set up an email address – Private Correspondence (private and obscure that you never publish in the public domain) and the public – for forums, chats, subscriptions to newsletters and so further;

– use only licensed software on your computer – often in pirated immediately sewed phishing program;

– place the protection against penetration on all devices, not just on a PC or laptop .

BTW

Check your account databases compromised accounts Yandex, Mail.ru and Google, please visit yaslit.ru. The creators of the site argue that it does not contain any information about the stolen passwords and saves your email address.

LikeTweet

No comments:

Post a Comment