We had *already* emailed everyone affected by the breach, and even made a public announcement (https://devkitpro.org/viewtopic.php?f=13&t=8846 …). There was no need to spread this any further.
-
-
Additional reminders are always a good idea. There is no harm in "spreading this further" because it has already been widely distributed; seeing the paste is more likely to provide benefit by getting people to change their passwords *now*.
1 reply 0 retweets 3 likes -
Spreading the password dump is going to result in increasing the chances of people's email addresses being noticed and passwords being bruteforced. Please delete the original tweet in this thread.
2 replies 0 retweets 1 like -
Anyone who wants to crack the passwords and own people already has the dump. Pretending they don't is security theatre. There is more benefit to be had by causing alarm and urging people to change their passwords *now*.
1 reply 0 retweets 5 likes -
And anyone who didn't have the dump before now does, due to this weak argument. Please retweet this without the pastebin dump. Your audience aren't just your followers on Twitter; there are abusive lurkers who do not hack for ethical reasons which follow you.
1 reply 0 retweets 2 likes -
Replying to @ha1vorsen @fincsdev and
Anyone who didn't have the dump can go to https://haveibeenpwned.com/ , type in the email address of *any* devkitpro forum user (e.g. mine, which is public), and follow the link to the pastebin. Sorry, I don't do security theatre. It's out there. Any and all attackers will have it.
1 reply 0 retweets 2 likes -
Replying to @marcan42 @ha1vorsen and
I get what you're saying but nobody is pretending the dumps aren't out there. Nobody is hiding what happened. This seems pretty irresponsible to me given your involvement in the homebrew scene and the likelihood of your followers having grudges against users in that dump.
1 reply 0 retweets 2 likes -
Replying to @davejmurphy @ha1vorsen and
If I mentioned it's in a Pastebin *at all* then any would-be wrongdoers will find it anyway. And if I don't, that would be irresponsible towards those affected. Given the decision to mention it, putting the link in everyone's face is only going to help drive the point home.
2 replies 0 retweets 0 likes -
Replying to @marcan42 @ha1vorsen and
I do understand what you're saying but it seems massively risky to me, I don't really see why people are less likely to change passwords just because they can't see a link to their data.
1 reply 0 retweets 0 likes -
Replying to @davejmurphy @marcan42 and
The dump you've linked to is also only a partial dump so, following your own argument, aren't users that aren't in this dump likely to gain a false sense of security?
1 reply 0 retweets 0 likes
It would be rather silly to assume that just because your name isn't in the dump you're safe. The point is the data is being shared. The contents are just showing this fact clearly.
-
-
Replying to @marcan42 @ha1vorsen and
Of course it would but people do crazy things every day. Like me. Not changing passwords on accounts I've had for years that I don't use much :/ We're going to go round in circles on this one though. Clearly you think the benefits outweigh the risks here & I don't
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.