Some apps reset your password automatically (send you a password reset email) if they detect it has been leaked.
But email services appear to have a harder problem due to the catch 22 where you can't log in to reach the password reset email if they were to reset your password.
Ignoring the backup email case as the other commentor left. In practice accounts are not immediately compromised so there is enough time to send a reset to the original user.
You could also do things like having the reset require the user to have a token that was issued before the compromise to prove you were able to authenticate before the leak happened.
I skimmed the article. I skimmed several of the linked articles. No one says the source of the credentials, other than where people are buying and selling them. Where are google login credentials coming from? Malware I assume and nothing to do with a problem at google?
Uh oh. For a long time I've been giving myself the excuse that the only reason why I keep using Gmail is security - Google has never had these kind of breaches.
The argument is no longer valid, time to move off Gmail.
Semaphor|4 months ago
Primary article instead of shitty forbes blog spam.
jcattle|4 months ago
It is 183 million email (not gmail) addresses in the collection of which 14M haven't been seen before on have i been pwned.
This hackernews title should be changed. (Currently: 183M Gmail Passwords Leaked)
larholm|4 months ago
"Gmail Passwords Confirmed As Part Of 183 Million Account Data Leak"
EForEndeavour|4 months ago
nomilk|4 months ago
But email services appear to have a harder problem due to the catch 22 where you can't log in to reach the password reset email if they were to reset your password.
What do they do?
bfkwlfkjf|4 months ago
charcircuit|4 months ago
You could also do things like having the reset require the user to have a token that was issued before the compromise to prove you were able to authenticate before the leak happened.
comrade1234|4 months ago
bfkwlfkjf|4 months ago
The argument is no longer valid, time to move off Gmail.
jsnell|4 months ago
blitzar|4 months ago
Those are mine
readthenotes1|4 months ago
I hope you're using a site that requires at least 6 (but no more than 10) uppercase, lowercase, numeric, and special characters.
https://archive.org/details/ninebillionnames00clar