Тёмный

Victim explains how Amazon account was hacked using 'credential stuffing' 

KOMO News
Подписаться 257 тыс.
Просмотров 288 тыс.
50% 1

Опубликовано:

 

11 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 167   
@kylecurryyt
@kylecurryyt Месяц назад
This is a terrible news story. They did not explain what credential stuffing is or how the hacker got the information.
@DeepikaSharma-nr1wd
@DeepikaSharma-nr1wd Месяц назад
LOL I felt like I walked into someone else’s conversation…news story is terribly done.
@rslitman
@rslitman Месяц назад
In fact, the only reason I clicked on this video was to find out what "credential stuffing" is.
@ByteSizedSociety
@ByteSizedSociety Месяц назад
Also what is this rock you breach? Where do I go to find out if my password is leaked? I have 300 passwords with 300 different accounts. Does Komo mean that I should change 300 passwords today? And take 5-19 hours to do it?
@shaggydawg5419
@shaggydawg5419 Месяц назад
Yeah, that info is missing but easy enough to search. It's "credentials obtained from a data breach on one service are used to attempt to log in to another unrelated service." It only works if you use the same usernames/passwords for all online accounts.
@shaggydawg5419
@shaggydawg5419 Месяц назад
@@ByteSizedSociety Google "have i been pwned?" If you use 300 unique passwords, you won't have to change anything or just change 1 that's leaked.
@kaydixie5727
@kaydixie5727 Месяц назад
Safer to use a credit card than a debit card!
@buzz5969
@buzz5969 Месяц назад
Not really. Just dont leave the card active on any accounts. Add it, do your order, then delete it. Problem solved.😊
@seth7745
@seth7745 Месяц назад
@@buzz5969 It's safer because credit card companies will almost always take the hit on your behalf. Its a lot harder to reverse bank transactions and you are out your funds until its rectified.
@samanthabarber7434
@samanthabarber7434 Месяц назад
@@kaydixie5727 don’t have one only debit card
@SL-lz9jr
@SL-lz9jr Месяц назад
@@buzz5969no financial protection if debit cards are fraudulently used as it is tied to your cash. You’d have a hard time getting the bank to refill your checking account. Credit cards operate on a credit system and not a cash system so banks can simply cancel the transactions and you don’t owe the bank any money for the fraudulent transactions.
@flashflame4952
@flashflame4952 Месяц назад
Absolutely correct!!!
@buzz5969
@buzz5969 Месяц назад
I order almost everything online, but I DONT leave any cards active in my accounts. I add them do my orders then immediately delete them. Cant charge to an account that has no chargeable cards.😊
@reginabillotti
@reginabillotti Месяц назад
@hughjaanus6680 So he missed a comma. The comment is still readable.
@julie3895
@julie3895 Месяц назад
@hughjaanus6680typos happen
@ChintanCG
@ChintanCG Месяц назад
Lot of sites won't allow you to delete a primary card
@KatTre
@KatTre Месяц назад
@hughjaanus6680 WOW! Get over it!
@juicewrld9867
@juicewrld9867 Месяц назад
It's ok if you leave a said prepaid card on the account that is empty and delete the card like the dude said that you actually have money on, the issue with his strategy is the scammers also obtained the email password ​@@ChintanCG
@mackmckay588
@mackmckay588 Месяц назад
Won't some hacker simply hack into a password manager app and then have access to all passwords for an individual? Why would a password manager be considered secure when it has so much vulnerability of having all passwords in one place?
@seattlekarim964
@seattlekarim964 Месяц назад
2FA and more complex passwords. Password managers greatly reduced the practice of using the same password on multiple sites.
@PilotVBall
@PilotVBall Месяц назад
Not the answer 🤦🏻‍♂️​@@seattlekarim964
@aa-hj2fd
@aa-hj2fd Месяц назад
If you don't hook your password manager to your browser or any application, it is reduces the possibly of getting hacked through the web to the manager: meaning everytime you need a user id and password, you have to manually populate the fields. If you get a good password manager, it will have a feature that deletes your clipboard after a few seconds, so that you don't have to manually. I would also avoid any password managers that require a online login (cloud type) for syncing purposes.
@StevenTorrey
@StevenTorrey Месяц назад
It floored me when I learned that every day, someone in the world is attempting to gain access to my computer. EVERY DAY!
@John_Doe3
@John_Doe3 Месяц назад
What is "credential stuffing" and how exactly was the "hacker" able to gain access to their account?
@SL-lz9jr
@SL-lz9jr Месяц назад
Right. The most important pieces of the story weren’t explained
@222aint
@222aint Месяц назад
Credential stuffing is password reuse, where these folks used the same password on different accounts and websites, because it is easier. Don’t do this. Use a password manager to create and store long complex passwords for each website and bank accounts. And use 2FA (two factor authentication) with an app on your cellphone like Authy or Google authenticator.
@Random_Identity
@Random_Identity Месяц назад
It’s the reuse of passwords across accounts. The user’s AT&T password was the same as their Amazon password.
@shellz831
@shellz831 Месяц назад
Its the MOST USELESS VIDEO on the internet.
@phyllissalazar8344
@phyllissalazar8344 Месяц назад
How anyone can not use multi factor authentication these days is beyond me.
@7415_Gamer
@7415_Gamer Месяц назад
Just cumbersome when you have many internet accounts.
@MissEAG
@MissEAG Месяц назад
Don't do two factor authorization where they send it to your phone though because if your phone is stolen - you're up sheets creek.
@NotYoung3592
@NotYoung3592 Месяц назад
@@MissEAG No you won't. Because if your phone is stolen, you aren't making any orders. Verification is only good for a few minutes anyway.
@shaggydawg5419
@shaggydawg5419 Месяц назад
if you use your cellular phone number as a second factor, it is actually worse in the event of SIM swap.
@Here4TheHeckOfIt
@Here4TheHeckOfIt Месяц назад
​@@MissEAG Gotta enable find phone and lock your phone. Many people don't do this
@ElizabethV187
@ElizabethV187 Месяц назад
Amazon has never asked to confirm a purchase before I've been shopping since 2018 Smh
@firstname__lastname
@firstname__lastname Месяц назад
I never leave my cards on Amazon. If I buy anything, I upload my card and then take it down each time.
@stargoddess2344
@stargoddess2344 Месяц назад
Great idea I will try that going forward
@johnp139
@johnp139 Месяц назад
How paranoid and inconvenient.
@stargoddess2344
@stargoddess2344 Месяц назад
@@johnp139 that is what your bank tells you to do, then you do not worry about a breach or hack. Trust me I have viewed all kinds of information of others viewed online by accident
@shaggydawg5419
@shaggydawg5419 Месяц назад
@hughjaanus6680 Find an opening on your device and insert it... it will upload. If you can't find it, shred the card into small bits.
@techshabby0001
@techshabby0001 Месяц назад
When will we hear they finally broke into the password manager system? Because you know they're working on it every second of every day.
@PliskinYT
@PliskinYT Месяц назад
Lastpass had like 3 hacks in the past 2 years
@something875
@something875 Месяц назад
Good point:(
@AK13133
@AK13133 Месяц назад
Somehow my wife had her account attached to another person and we started getting crazy purchases but they were actually coming to our address. They ended up reimbursing us but it was a major pain to deal with. Now I’m scared every time I check the bank
@MissEAG
@MissEAG Месяц назад
Don't do two factor authorization wherer they send it to your phone though because if your phone is stolen - you're up sheets creek.
@vickilindberg6336
@vickilindberg6336 Месяц назад
Amazon has been pretty god for me up to now. An on line account anywhere is always in danger.
@shaggydawg5419
@shaggydawg5419 Месяц назад
Amazon suggests re-entering card for payment? Why? I removed mine from my Amazon account. No reason to keep it saved there so criminals can shop using my card.
@Adventures_of_Marshmallow
@Adventures_of_Marshmallow Месяц назад
Passwords aren't inherently weak. Implementation by the web service is. Blows my mind multi-billion dollar companies still can't get routine authentication right.
@shaggydawg5419
@shaggydawg5419 Месяц назад
you can spend a trillion or quadrillion on technology... idiots will still fall for a simple social engineering trick. Sure in the case of rockyou2024 it has nothing to do with tricking users.
@OfficialDJTasawennateken
@OfficialDJTasawennateken Месяц назад
Had the same thing happen to me only the people tried to order computer and I'm broke and don't have money so they couldn't do anything in Amazon caught on to it
@gailmckay5551
@gailmckay5551 Месяц назад
This stuff is why I buy a Amazon card for the amount of my purchases or as close to it as I can. That leaves them not much to steal.
@CharleyTank
@CharleyTank Месяц назад
*Don't use a password manager because they get hacked* keep passwords on an encrypted flashdrive
@smc5429
@smc5429 Месяц назад
I keep passwords on a sheet of paper. I dare someone to hack that. Good luck reading my writing, better bring your magnifying glass.
@CharleyTank
@CharleyTank Месяц назад
@@smc5429 hahaha very good.
@vmobile890
@vmobile890 Месяц назад
A good password is a hint of something sometime somewhere long ago . What was of brand of underwear I wore in 1960
@CharleyTank
@CharleyTank Месяц назад
@@vmobile890 Yeah can't hack Hanes Underwear LOL
@jeanp.5929
@jeanp.5929 Месяц назад
This is a good idea. Now I have to learn how to encrypt a flash drive. Also, what kind of text file would be good to use? MS Word, .txt? I'm thinking a pdf file wouldn't be good since a web browser can be used to read it.
@user-nb5sv7cr6g
@user-nb5sv7cr6g Месяц назад
Then.... they advise you to give all your new passwords to a "Data Manager", hello.....you're still giving your information to someone else! Don't so it! Just be old fashioned, change all your passwords, make them tough, and write them down on a piece of paper and stick it in your wallet! Or better yet, your BIBLE! No one will ever find it there.😂
@aracoixo3288
@aracoixo3288 Месяц назад
Credential stuffing: brute force password cracking. They just keep guessing til they got it.
@CrabbyOldLady
@CrabbyOldLady 4 дня назад
Unless of course the account gets locked after a certain number of failed attempts.
@melissawingfield8666
@melissawingfield8666 Месяц назад
So what is "credential stuffing?" It's in the title but not explained.
@gFamWeb
@gFamWeb Месяц назад
Its not a data breach. It's a password file.
@stand4truth607
@stand4truth607 Месяц назад
And people want to implant chips into their brains...
@blahco4tt
@blahco4tt Месяц назад
There was an Outer Limits episode from back in the 90s that was about that, although I can't remember if hacking was involved, but there was some sort of problem with the chip-- and just about everyone had one.
@flashflame4952
@flashflame4952 Месяц назад
MOST legit companies DO NOT contact the customer, amazon is one of them. And NEVER use your debit card!!!! To much access to your $$$.
@ElizabethBanks-tu8wo
@ElizabethBanks-tu8wo Месяц назад
Amazon forces me to keep a creit card on file because they charge me for prime every month
@alansmith5255
@alansmith5255 Месяц назад
When are people going to learn do not use debit cards they are junk you don't have the same protection as a credit card
@russcrawford3310
@russcrawford3310 Месяц назад
So companies who collect personal information can just keep selling it?" ...
@justme274
@justme274 8 дней назад
Amazon needs to get new security online.
@heatherhayes9498
@heatherhayes9498 Месяц назад
My packages were stolen… a laptop please investigate 🙏
@theadventuresofjohnandjennifer
@theadventuresofjohnandjennifer Месяц назад
Lock your debit and credit cards. So easy.
@mgkelly3389
@mgkelly3389 Месяц назад
Lousy work. You really should do a better job for your audience. Start with the who, what, when, and where.
@user-ek9ct8cw4d
@user-ek9ct8cw4d Месяц назад
Inside jobs.
@reoffending
@reoffending Месяц назад
Dumbest comment I’ve ever read
@skipjack6974
@skipjack6974 Месяц назад
Already got my alert, thankfully NONE of my passwords re text only. I use numbers, letters, and characters. My husband and I also use numbers or letters switched. Like 8 for a B or E for the number 3. Remember just be creative.
@user-iq9df7eb1q
@user-iq9df7eb1q 3 дня назад
What a shame.
@susanrand512
@susanrand512 Месяц назад
I took my credit card info off Amazon last month.
@samanthabarber7434
@samanthabarber7434 Месяц назад
I’m getting emails of someone using my PayPal account on eBay and other places how can you protect yourself?
@dw3403
@dw3403 Месяц назад
Yikes your card info off until you need it. Let PayPal know.
@samanthabarber7434
@samanthabarber7434 Месяц назад
@@dw3403 thank you
@reginabillotti
@reginabillotti Месяц назад
Those emails may not be legit. They might be part of a scam. Make sure you aren't responding to them - instead, check your paypal account or directly with your bank to see if there have been any fraudulent charges made.
@bhambhole
@bhambhole Месяц назад
Possibly a scammer trying to trick you. Always verify it's really PayPal and never ever install software if they ask you to.
@cyrysvonnachtseite4546
@cyrysvonnachtseite4546 Месяц назад
Great job to the cyber security…. Thanks ….
@MichelleChristianson-zx5tm
@MichelleChristianson-zx5tm Месяц назад
My account from amazon was hacked, from someone in mexico
@TheSuzberry
@TheSuzberry Месяц назад
Shopping Amazon isn’t safe?
@miketrissel5494
@miketrissel5494 28 дней назад
A PASSWORD MANAGER? Isn't that a program from a third party that stores your passwords online for you, so that hackers can access all your passwords in one place, and sell them for profit?
@chaostheory613
@chaostheory613 27 дней назад
Someone takes your laptop and this is how you cover up?
@bobtail1200
@bobtail1200 Месяц назад
You think so ,really . This country has been hacked since the HAL 2000 was revealed
@Crokatec
@Crokatec Месяц назад
Journalism these days...
@donnapowers9892
@donnapowers9892 9 дней назад
WHT IS CREDENTIAL STUFFING??
@zeke5491
@zeke5491 8 дней назад
Makes you want to go all in on the digital dollar-NOT!
@bmaiceman
@bmaiceman Месяц назад
I dont use credit cards. I buy a giftccard forcexaft amount needed.
@Notwoke7
@Notwoke7 26 дней назад
4 hours lucky him! I've been dealing with this 3 months and how to contact the Attorney General
@bldsprt518
@bldsprt518 Месяц назад
Imagine the government actually doing their job and protecting people rather than all the other nonsense they keep busy with.
@spiritmoonintuitive
@spiritmoonintuitive Месяц назад
I called amazon just to ask a question. The guy says you need to start an account & put in your payment method; I'll hold while you do that. I hung up. I've never done business with amazon, and never will.
@elfuturomio
@elfuturomio 9 дней назад
Ohhhhhh nooooooo not Amazon
@wakethesaints
@wakethesaints Месяц назад
Just happened to me
@yolinagarr5144
@yolinagarr5144 Месяц назад
What? 😳
@deepuisin
@deepuisin Месяц назад
These for those people , who just buy everything online. & put their details here their even QR scanning is a bug scam too. Soo just take care, & buy wat is necessary.
@Bofiddleydiddley
@Bofiddleydiddley Месяц назад
simply stop purchasing anything on line
@buzz5969
@buzz5969 Месяц назад
I purchase everything on line..
@kakishisfriend1126
@kakishisfriend1126 Месяц назад
There are skimmers in real life too
@reginabillotti
@reginabillotti Месяц назад
Hope you don't live in a small town with barely any retail. Or don't want or need anything like airline tickets that can't be purchased in person.
@fdavidmiller2
@fdavidmiller2 Месяц назад
@@reginabillottiagreed, except you can definitely buy tickets in person at any airport.
@reginabillotti
@reginabillotti Месяц назад
@@fdavidmiller2 Yes, but it's a lot more cost effective to buy in advance whenever possible. And for me, it's too long of a drive to the nearest major airport to make a trip just to get tickets. So yeah, maybe "can't" was a little oversimplification, but it's basically true.
@2011Savere
@2011Savere Месяц назад
And they want to push all this AI.
@HopliteSecurity
@HopliteSecurity Месяц назад
The old Amazon scam!
@akenjah
@akenjah Месяц назад
It's not a scam it's a security breach that the hackers are getting into.
@fluxfaze
@fluxfaze Месяц назад
Don’t leave a payment method in Amazon. Use it then delete it right away after the purchase has been completed.
@Kathylopex-gf2uq
@Kathylopex-gf2uq Месяц назад
Best Sassy Realistic Advice, stop shopping online and start shopping in person., Furthermore, I guess the saying is true, although online shopping tends to be very affordable aka cheap at the end, it becomes a costly financial loss experience.,
@vmobile890
@vmobile890 Месяц назад
Shop in person great advise what’s the local stores name with everything Amazon sells ?
@Bee_Mavrick
@Bee_Mavrick Месяц назад
Cia at it again
@AmandaOwen-n9r
@AmandaOwen-n9r Месяц назад
I never keep any payment information on any site. I always keep my cards locked as well as my credit cards. Paying for password encryption is worth the money.
@Meant2BVegans
@Meant2BVegans Месяц назад
Storing your passwords is how hackers get them, so just enter them manually every time.
@janncoons7445
@janncoons7445 Месяц назад
That's what you get for feeding the Beast I've never ordered anything from Amazon
@MissylovesTrouble
@MissylovesTrouble Месяц назад
It's not just Amazon this is happening on.
@Kr0nicDragon
@Kr0nicDragon Месяц назад
Can’t get hacked if you go to an actual store and buy it with cash. You’ll receive it faster then next day shipping too. Heaven forbid you use your legs tho.
@shanna1518
@shanna1518 Месяц назад
EXACTLY very well said👍👍👍
@reginabillotti
@reginabillotti Месяц назад
If there is a store that sells the product you want, that is. That won't always be the case. And some things you can't buy from a store (e.g. airline tickets). Besides, cash is not always perfect. You can be mugged. You can also fall victim to phony credit card readers at ATMs. (Look up "card skimmers" to learn about this)
@222aint
@222aint Месяц назад
ok boomer
@Bobbillyjrboy
@Bobbillyjrboy Месяц назад
Unfortunately we don’t live in the 70’s anymore
@sannotutamime-k3w
@sannotutamime-k3w 8 дней назад
Anderson Ruth Taylor John Perez Jeffrey
@johnp139
@johnp139 Месяц назад
What good is a complex password when the passwords were exposed?
@purplepeoplesparty2368
@purplepeoplesparty2368 Месяц назад
Cyber cat and mouse game continues.
@syntheticfuture1718
@syntheticfuture1718 Месяц назад
Далее
The Evil Design of Japan's Death Penalty
9:54
Просмотров 2,9 млн
Дежавю, прескевю и жамевю!
00:59
Standoff 2 is a true horror! #standoff #horror #meme
00:13
Китайка и Зеленый Слайм😂😆
00:20
NEVER install these programs on your PC... EVER!!!
19:26
How you get Hacked: what attackers use today
9:02
Просмотров 168 тыс.