You expect password reuse to be a small risk
WeTheNorth addresses
hn2paw7zadwkcra3qzv5e4q547i7e5lvxm62cfxqftuqdu7moiu2ceyd.onionhn2paw7zfvndw3dovycegeqmvvnf4pl67b3g2p7pohjlzavloosh73id.onionhn2paw7zrgujyhnt6mgxlt2q6uhgbke4itpqitxhyfbumq3wtnckbuyd.onionPrinted as supplied, in no order. Nothing here is checked or timed, so an address that opens is not proof of anything. more about the set
Nobody is targeting me. Reusing a password I remember is a reasonable trade.
Nobody needs to target you. Old breach lists get replayed at scale, and a password you used somewhere else in 2019 is already in one of them.
The gap: you are picturing an attacker who picked you. The attack is a loop over a file.
What the attack actually is
Take a list of usernames and passwords from an old breach. Try each one against a login form. That is it. There is no cleverness and no target selection. The economics work because the list is free and the success rate does not need to be high.
The reason people underestimate it is that they imagine a person deciding to attack them. Nobody decided anything. A machine worked through a file and your line came up.
Why the local situation is worse
- There is no email alert when a login happens from somewhere new, because there is no email.
- There is no support path to freeze an account while you sort it out. See support will answer.
- There is no reset to lock the intruder out afterwards, for the reasons in the recovery entry.
- Anything sitting as a balance can be moved before you notice, and a balance sits outside every protection.
On an ordinary site a stuffed login is an inconvenience with a recovery process. Here every part of that process is missing, which turns the same event into a permanent loss.
The username matters too
People reuse handles more than passwords, and a handle is a thread. A name used on a forum in 2016 and again here connects two records that had no business being connected. Search engines remember old profiles for a very long time, and so do archives. Pick a name that has never existed anywhere else and has no personal meaning at all.
What to do
- A unique password, generated rather than invented. Human invented passwords cluster around the same patterns.
- A unique username with no history. This costs nothing and closes a whole class of linking.
- Store both offline, with the signup material from registration, in the same place and the same handwriting.
- Turn on whatever second factor the platform offers and store the backup for it the same way.
The objection is always that a long random password is hard to remember. It is, and remembering it is not the job. The job is having it written down somewhere that survives a lost phone, which you already need for the account material anyway.
One detail people get backwards. Changing a password regularly does very little here, because the attack is not somebody slowly guessing yours. Changing it after any hint that a login happened without you is worth doing immediately. Frequency is not the useful variable. Uniqueness is, and it only has to be got right once.
Questions people send about this
Is a password manager safe to use for this?
A local, encrypted, offline one is a reasonable tool. A manager that syncs through an account tied to your name puts a list of your logins under that name.
What if I only reused it on a harmless site?
The harmless site is the one that got breached. That is the whole mechanism.