- cross-posted to:
- securitynews@infosec.pub
- cross-posted to:
- securitynews@infosec.pub
I just got the email from haveibeenpwned. F Trello.
Oh no not my email adress and username
Hello spam, and also confirmation that your email address and username is valid and can be used to try to log in elsewhere.
Obligatory: companies should face harsh penalties for this stuff.
Yes but this wasn’t a data breach. This was a data stuffing incident, meaning they took someone else’s data dump and tried their email and credentials here.
- never use the same username and password in two or more places
- always use MFA, a hard token if you can like a yubikey
Do you own a Yubikey?
Have you ever succeeded in getting it to work with anything??
It didn’t work with gmail, or any other online account I had.
An absolute waste of $$.
15M Trello accounts have been leaked
That title is very misleading. 15M Trello accounts were found to be compromised because of other, previous leaks, but no leak related to Trello occurred.
This should be a locally installed program with a licensing usb dongle or electronic license.
So much company secrets in there…
Dang, the hackers know what I’m planning to do tomorrow.