Discord.io got hacked!

  Рет қаралды 341,972

No Text To Speech

No Text To Speech

Күн бұрын

Discord.io is NOT Discord.gg / Discord.com! But this hack / data breach does affect Discord users that may have used Discord.io (yeah it's confusing)
Discord.io, a website like top.gg and disboard.org that allows you to advertise your server as well as create free vanity invite links, got breached. 760,000 users had their information uploaded to the . This information includes emails, Discord IDs, salted and hashed passwords, and finally your billing information if the conditions are right.
LINKS
-----------------------------------------------------------------------------
KeePass
keepass.info/
Bitwarden
bitwarden.com/
Proton Pass
proton.me/pass
iCloud+
www.apple.com/ca/icloud/
CloudFlare Email Routing
www.cloudflare.com/developer-...
SOCIALS
-----------------------------------------------------------------------------
Discord Server
/ discord
Twitter
/ notexttospeech
TIMESTAMPS
-----------------------------------------------------------------------------
00:00 - 1. What is Discord.io?
00:49 - 2. What information was exposed?
02:50 - 3. What should you do?
04:40 - 4. How to stay safe(r) from databreaches
06:57 - 5. How stupid is this?

Пікірлер: 692
@NoTextToSpeech
@NoTextToSpeech 10 ай бұрын
One reason Discord.io could be holding onto old billing data is for auditing reasons. For example a bot dev told me they are required by law to keep user billing details for 5 years. Also, reversing your password from a salted and hashed password is very difficult even if you have a simple password. However I would still change passwords because it's a good practice. Also I forgot to point out that if you use the same password and your email is in the breach, someone could check if your password has been exposed in a different data breach. If it has, they could try to guess your password and get into your other accounts.
@bz_zq
@bz_zq 10 ай бұрын
crazy
@cl4pre
@cl4pre 10 ай бұрын
this is the problem with trusting websites nowadays it's just hard
@SillyGIFs
@SillyGIFs 10 ай бұрын
:(
@preum526
@preum526 10 ай бұрын
This is why i have trust issues.
@Firelight7118
@Firelight7118 10 ай бұрын
Welcome to the internet. Nowhere is safe.
@local9
@local9 10 ай бұрын
They did well at least to take action, more than most mega corporations.
@blinking_dodo
@blinking_dodo 10 ай бұрын
As far as i can see, they have done it completely right. They have handled this issue over a thousand times better than many megacorps did.
@poopmaster
@poopmaster 10 ай бұрын
​@@blinking_dodothis is because they aren't a mega corporation
@ahpjlm
@ahpjlm 10 ай бұрын
@@poopmasteryeah, don’t get why they calling discord a mega corp Alphabet (Google‘s parent company), Apple, Microsoft, Amazon are mega corps, because they are worth trillions and have several subsidiaries and large market shares
@TheJinx64
@TheJinx64 9 ай бұрын
mega corporations do the same thing? im all for bashing the executives but this is just not true
@CCRandomBN
@CCRandomBN 10 ай бұрын
Honestly bro you deserve an award for informing us EVERY SINGLE TIME
@RammansPizzas
@RammansPizzas 10 ай бұрын
@@enzoshorts. Says the guy who makes fake YT Shorts content
@user-kb9oy9nn2l
@user-kb9oy9nn2l 10 ай бұрын
@@enzoshorts.why does bro comment shit on every one of his videos bro you have no rights your yt channel is lit fake Roblox vids please stfu and go back to adopt me
@stromchaser32
@stromchaser32 10 ай бұрын
@@enzoshorts. lmao yt shorts creator. irrelevant moment
@Midway64
@Midway64 10 ай бұрын
@@enzoshorts. Not even the checkmark will save you from invalidating your opinion!
@doge_voador
@doge_voador 10 ай бұрын
@@enzoshorts. Shorts creator = brainrotten individual
@Kozakow
@Kozakow 10 ай бұрын
He hates discord users, so he became the ultimate discord user.
@wiccansubs5031
@wiccansubs5031 10 ай бұрын
LMFAOOO
@sunseyki.
@sunseyki. 2 ай бұрын
305 likes and only 1 reply?!lemme fix that also, yeah that's really funny. the irony
@nomoretwitterhandles
@nomoretwitterhandles 10 ай бұрын
I saw "data breach" and felt worried, but as soon he explained discord,io I realized this has nothing to do with me because I don't use 3rd party discord stuff lol. Thanks for always informing us about these things (and general safety tips, like the password thing).
@jinnipers.3931
@jinnipers.3931 10 ай бұрын
in his attempt to say he hated discord, he sounded like he came straight from it 😟
@AndriuxDev
@AndriuxDev 10 ай бұрын
Well, it's like they said: *That little boy... is in BIG trouble.*
@EdyAlbertoMSGT3
@EdyAlbertoMSGT3 10 ай бұрын
He sounded more like a twitter user
@EmmyVR
@EmmyVR 10 ай бұрын
Hahaha, this combined with discord’s dumb little “Free boosts” thing is gonna cause alts to be wayyy too easy to get lol
@maker0824
@maker0824 10 ай бұрын
Hopefully the type of people who used that website are the type of people smart enough to not fall for that. Hopefully.
@AndriuxDev
@AndriuxDev 10 ай бұрын
Hahaha, you fool. I HAVE 700 ALTERNATE ACCOUNTS!!! 😈 /jk
@MrEelement
@MrEelement 10 ай бұрын
@@AndriuxDevme after I figured out to put a + at the end of my email then the account name 😂
@CDJAM-webm
@CDJAM-webm 10 ай бұрын
@@AndriuxDev eeerm its actually 70
@itagamineko
@itagamineko 10 ай бұрын
Generally your data might already have been sold (passwords n stuff) so its best to check a specific site that lists data breaches on websites and change passwords accordingly
@20thCY
@20thCY 10 ай бұрын
I should probably check the site because 760K users mean more likely than not they have my info
@officialromanhours
@officialromanhours 10 ай бұрын
I'd recommend checking "have I been pwned" as soon as they get a copy of the data
@20thCY
@20thCY 10 ай бұрын
@@officialromanhours Oh I will
@1boo
@1boo 10 ай бұрын
as far as i am aware i don't think there are sites that list databreaches with the passwords
@20thCY
@20thCY 10 ай бұрын
@@1boo Even then, most users won't get their passwords leaked during this since most are newer users
@Jennn
@Jennn 10 ай бұрын
Man you did an amazing job explaining exactly what happened, what everything means. I especially liked your explanation on the salted and hashed passwords. Thank you for this. Great work!
@brujyyy
@brujyyy 10 ай бұрын
Btw, for hashed passwords, you can't "reverse engineer" it quite easily as it requires the original password (didn't leak) and salt (that leaked) to check if the hashed password is the same as the stored one. So don't worry about your password.
@user-a0d9w0ec9wiej
@user-a0d9w0ec9wiej 10 ай бұрын
I would still recommend changing the password tho
@zipf
@zipf 10 ай бұрын
it can still be bruteforced
@wedoalittletrolling723
@wedoalittletrolling723 10 ай бұрын
@@zipf will take over 10000 years depending on how strong the victim's password is
@chri-k
@chri-k 10 ай бұрын
@@wedoalittletrolling723most people have a weak password
@susibaka
@susibaka 10 ай бұрын
Yup, they can't reverse it, that's why it is used
@PinkAgaricus
@PinkAgaricus 10 ай бұрын
I really feel like that person is in their early 20's going into 18+ servers and chats and complaining about it, then subsequently doing this. I feel like as much as he says he hates discord and the people on it, he used it at some point to get angry at users and create a motive to do this breach.
@jort93z
@jort93z 10 ай бұрын
Just in general DONT use the same password on multiple sites, except if you really don't care about the account I guess. There is nothing assuring you the person running the website doesn't simply sell your password.
@Splarkszter
@Splarkszter 10 ай бұрын
Thank you for keeping us safe. Much appreciated.
@fusionsid270
@fusionsid270 10 ай бұрын
with salted and hashed passwords it's basically impossible to reverse engineer it. Though what hackers would do it try to brute force it, basically if they have the salt and know the hashing algorithm they can try the most common passwords or combinations and feed it through the hashing algorithm then compare it with the hash produced. The salt is usually stored appended or prepended to the hash so getting the salt won't be difficult. If have a very strong password you shouldn't need to worry much about your password being compromised. Because if your password isn't in a word list or isn't common or short they will have to try every combination eg aa, ab, ac, etc and this quickly adds up. However you should still change it just in case. Especially if you're using the same password on multiple websites.
@Herobrain1000
@Herobrain1000 10 ай бұрын
GG on 500k you are amazing :))
@WASTOIDSUPREME
@WASTOIDSUPREME 10 ай бұрын
I'm glad I've been juggling 70 different emails for the past 10 years (yes I frequently forget them all the time).
@utopes
@utopes 10 ай бұрын
You have 70 alternative accounts
@WASTOIDSUPREME
@WASTOIDSUPREME 10 ай бұрын
@@utopes I've been on the internet for a while.
@AvidEscaper
@AvidEscaper 10 ай бұрын
Do you make robots by any chance?
@stanimirborov3765
@stanimirborov3765 6 ай бұрын
I barely wrote on a notepad how many sites ive registerd on... mm ive figured a way for unique passwords not to be wriutten down or forgotten but dont wanna share..well maybe on stanimir borov1 my first utube channel i might release som video of ideas but not sure yet@@utopes
@clout9661
@clout9661 10 ай бұрын
Petty people doing petty things, I wish we had some way to find the dudes info and get him arrested for this stuff.
@sodicious
@sodicious 10 ай бұрын
Just send a pipebomb where they host that database breach website
@pattyguy
@pattyguy 10 ай бұрын
@@sodicious well lol breachforums is another honeypot anyways
@filipetrujeira3359
@filipetrujeira3359 10 ай бұрын
@@pattyguy Since Pom was arrested it became one.
@UndercoverDog
@UndercoverDog 10 ай бұрын
​@@filipetrujeira3359we dont know 100% if it is. Its very likely tho.
@justforrow
@justforrow 10 ай бұрын
Petty? They did it for the money.
@SillyGIFs
@SillyGIFs 10 ай бұрын
No Text To Speech is the best channel about discord I've ever seen, thanks!
@discord-cats
@discord-cats 10 ай бұрын
Yes:)
@Haiiacat
@Haiiacat 10 ай бұрын
Yes!
@Nx-tagames
@Nx-tagames 10 ай бұрын
Beluga is better
@Laiteux
@Laiteux 10 ай бұрын
@@Nx-tagames absolutely not the same kind of content tho
@Writer_Productions_Map
@Writer_Productions_Map 10 ай бұрын
​@@Nx-tagameshow?
@sinstreams
@sinstreams 10 ай бұрын
The aliasing service that proton uses (and owns) is simplelogin. Just for those who are curious. 6:15
@sinstreams
@sinstreams 10 ай бұрын
An issue with iCloud+ hide my email is that you can’t email support from that alias email. This might make things harder to manage if you’re trying to contact discord support or whatever support you might need to email using that alias you create. 6:34
@petertrex
@petertrex 10 ай бұрын
Use password manager, use 2FA, use email aliases. take security measures. like that's only things you can do. most people stops at pw manager and 2FA, but this is the very reason you want to use email alias, so you don't have to worry about anything and just shut that one off.
@JessicaFEREM
@JessicaFEREM 10 ай бұрын
Good on you for using FOSS software like bit warden
@niskicovjek
@niskicovjek 10 ай бұрын
how do you keep beeing entertaining while teaching us stuff boa?
@komunich
@komunich 10 ай бұрын
Phew.. i felt like im about to lose all of my accounts but ive been wrong. thanks for telling us!
@abcdefgh1795
@abcdefgh1795 10 ай бұрын
always a good day when ntts uploads
@Coltonfr5
@Coltonfr5 10 ай бұрын
lmao
@uglen7420
@uglen7420 10 ай бұрын
how do these shitty comments still get likes
@pomurain
@pomurain 10 ай бұрын
what in the spam bot is this message
@olek0
@olek0 10 ай бұрын
alswyahsn agopsdkda day wehn ntns ahuopad;ls
@CharlieDennisonUrmom
@CharlieDennisonUrmom 10 ай бұрын
Agree
@lisaruhm6681
@lisaruhm6681 10 ай бұрын
Note for billing adresses, country dependant, a company has to keep all its money transactions for 5+ years.
@denis2381
@denis2381 10 ай бұрын
Yeah in my country it is 7 years
@agentgato9854
@agentgato9854 10 ай бұрын
for differenting passwords i wold use an algorithm for the password containing some static elements combined with some variable characters that involve the websites middle 3 characters moved 1 right and 3 down on the qwerty keyboard
@dogeimpala
@dogeimpala 10 ай бұрын
You know it's forgettable when all the top comments are generic "always a good day when ntts uploads"
@nebuloxxx
@nebuloxxx 10 ай бұрын
Loving these videos!
@terbospeed
@terbospeed 10 ай бұрын
I have to wonder what circles this person was running in to think that half of discord is pedocontent... I've used it for several years and not really run into it, meanwhile on reddit, twitter, and facebook, 4chan.. the opposite is true.
@scarletrevolt
@scarletrevolt 5 ай бұрын
Oh buddy, you would be surprised on how much pedo content is in Discord. Not just that, but grooming, zoos, etc. Like just cause you didn't see it doesn't mean it ain't out there.
@nateholden7598
@nateholden7598 10 ай бұрын
I usually use long and complex passwords for every app/website and different emails. I suggest you use similar characters such as L and i "lI" or O0 ECT. And I tend to make my passwords stupidly long. We're talking at least- What? 10 or 15 characters? And maybe even 40 for some. With a password that's long and has a lot of characters that look alike, 2FA, And a different Email for EVERYTHING. That's about as secure as you can get to my knowledge. Of course me having anxiety I still question how Secure my stuff is and keep making my passwords longer and more complex.
@th0master
@th0master 10 ай бұрын
5:10 personally I just use the password manager that comes with iCloud, works great on your Apple devices, but there are also extensions for Chrome and Firefox
@hadesbutyoutube
@hadesbutyoutube 10 ай бұрын
iCloud+ also lets you do the custom email addresses if you're already using that.
@CLRBLNDN
@CLRBLNDN 10 ай бұрын
Just tried to join a server and it wanted me to add a bot that would join servers for me. Thanks man
@Mar_Ten
@Mar_Ten 10 ай бұрын
The hashing algorithm is really important to determine if something is safe or not.
@pongo-7111
@pongo-7111 10 ай бұрын
on email forwarding anonaddy is pretty good but some companies have started to blacklist using forwarding/relay alias so you might need a backup or 2nd email regardless
@Wilker_uwu
@Wilker_uwu 10 ай бұрын
there's STILL websites that adopts whitelisting of email domains instead which is bs
@catuaa
@catuaa 10 ай бұрын
just use skiff and be happy
@erikkonstas
@erikkonstas 10 ай бұрын
What you're describing is unfortunately a cat-and-mouse game; relays continually create aliases, and the other companies continually hunt them down.
@zeratax
@zeratax 10 ай бұрын
simply reverse engineering a salted and hashed password is some nation state kinda work, not impossible but insanely difficult (if they followed best practices that is lol)
@erikkonstas
@erikkonstas 10 ай бұрын
I mean, even if the salt is a constant the hackers would still have a harder time...
@bandiddums
@bandiddums 10 ай бұрын
About email relays I watched a video about that from Thiojoe and there is a feature where you put some special annotation in your existing email to make it. So it's the same email but with a different address. Though I do remember that he said the feature is rarely supported on websites and all you have to do to get the original address is to just remove the annotation so it's pretty easily bypassed
@robertplayz9157
@robertplayz9157 10 ай бұрын
It's by putting a + and any string before the @ in the address. However in my opinion that's only good to counter email marketing/spam.
@Milenakos
@Milenakos 10 ай бұрын
@@robertplayz9157 indeed, anyone can remove + part and get your normal email with no issues
@thatdude9091
@thatdude9091 10 ай бұрын
And it can be ignored (they just remove the +)
@robertplayz9157
@robertplayz9157 10 ай бұрын
@@thatdude9091 telemarketers have many addresses to deal with, and their time for the money is precious to them, so they don't filter or sort, they just send.
@thatdude9091
@thatdude9091 10 ай бұрын
@@robertplayz9157 it takes a very simple filter to remove +
@Wither_Strike
@Wither_Strike 10 ай бұрын
Hash's are generally pretty safe as passwodd storing methods go. Its not impossible to crack, but generally the methodology would be to figure out what the hashing algorithm was, generate a wordlist that might contain the password needed, and hashing each of those passwords using the hashing algorithm and seeing if the hashs match. Salting a hash greatly helps, but people have cracked salted hash's before. Im too new to hacking to know how. Still a good idea to change your password, but also good to know that this is much better than them storing your password in plaintext, aka english
@HiHelloHi
@HiHelloHi 10 ай бұрын
Since salt should be unique to each account, you can't just easily use a precomputed table of hashes of common passwords to look for collisions. This means for each account you wish to crack, you'd have to recalculate hash(guess|salt) for each possible password you want to test for a collision. Modern hashing algorithms have a very low collision rate too.
@Wither_Strike
@Wither_Strike 10 ай бұрын
@@HiHelloHi i think thats a bit too high end language for me lol. this is why i try to do as little as possible with hashes lol
@HiHelloHi
@HiHelloHi 10 ай бұрын
@@Wither_Strike collisions are just when a different password hashes into the same digest (the output of the hash function) as the actual password. That is to say: hash(A) equals hash(B) where A and B are not the same password. This is due to the fact that hashes are compression functions, meaning they condense a number of character to the same length of hash for each input string of letters. A table of hash values is just a means to store the outputs of hashing commonly leaked passwords so that you don't compute them yourself. Salt makes it so you have to re-compute this table
@preum526
@preum526 10 ай бұрын
Just makes my day better 🍵.
@_lun4r_
@_lun4r_ 10 ай бұрын
good to know that i use a different custom vanity link service, and not this one i didn't get hacked
@oreooooo999
@oreooooo999 10 ай бұрын
You did a good job with this vid, but 2fa isn’t great if u get sim swapped etc
@Jellae
@Jellae 10 ай бұрын
I love it when trash human beings try and claim they are doing something for justice just to cover up their crimes. Like kid is calling everyone on an app a pedophile and thinks he is doing justice by SELLING their data 💀 This guy made 2 wrongs (1: Trying to make bank. 2: Calling an entire user base pedophiles) for 1 wrong (there are indeed SOME pedophiles)
@wasabitofu9491
@wasabitofu9491 10 ай бұрын
the nerd voice at the end THAT was a beautiful performance.
@gjorgix3224
@gjorgix3224 10 ай бұрын
What is the folder tabs thing you have in your browser? I've seen it in your videos and would love to use it.
@supernovaw39
@supernovaw39 10 ай бұрын
It's built into Chome and any Chromium-based browsers (Edge, Opera, Brave, etc.). You can right click any tab and "Add tab to group." You can pick colours and names for them
@gjorgix3224
@gjorgix3224 10 ай бұрын
@@supernovaw39 Thanks, I have been using a chromium browser for like 10 years and somehow I've never realised this
@Мопс_001
@Мопс_001 10 ай бұрын
That's why I made a bunch of measures to protect my useless discord account, even two of them.. It's a funny relieving feeling when having so much protection that breaking it would require a ton of efforts even after an exposed password Like, nobody would even dare (after entering it) to guess a 6 digit key that is re-generated (in other connected authentication app) every 30 seconds to pass through. Pure bliss. Wish mode people used that more often
@dashdashdash_
@dashdashdash_ 10 ай бұрын
Still doesn't mean there isn't a CVE that effects your router and can infect your machine via improper software or another exploit, from there cookie based attacks can be performed, rendering your protections null.
@Мопс_001
@Мопс_001 10 ай бұрын
@@dashdashdash_ I'm not an expert but it seems like something rather targeted and what's definitely not going to happen to random weirdo from the internet . Also what affects router sounds like something that should be quite local to be relevant, proper people could tell better. Whatever anyways, what I say is to improve common protection of your account, and replying by random "tHaT iS nOt gOiNg tO sAvE yOu as there is " is lame you know. Though you can of course not use any protection then, if that's what you ultimately tried to say.
@erikkonstas
@erikkonstas 10 ай бұрын
@@Мопс_001 It doesn't have to be targeted, that's why IP grabbers should scare you legitimately despite people saying "your IP isn't private blah blah"; the problem is *who* has your IP address! Also, router firmware updates are not always a thing.
@Мопс_001
@Мопс_001 10 ай бұрын
@@erikkonstas Again I hear only . I don't care about it and you all miss my main point. Use the damn protection, even if it's not going to save you from the airplane crush or end of the world. Unless you want to advocate against *this,* that's 0 worth of argument.
@erikkonstas
@erikkonstas 10 ай бұрын
​@@Мопс_001You're really ignoring the danger here, whilst at the same time advocating for having protection measures in place...
@joogled1839
@joogled1839 10 ай бұрын
i clicked on this because i thought i had USED the site before. so glad to know it only affects those who made an account on there. my prayers go out to you poor guys.
@samuelbi11
@samuelbi11 10 ай бұрын
content fast asf because of attention spam, nice video!
@neock
@neock 10 ай бұрын
as for password managers... using them is just as big a risk. because now, instead of needing to know one password for each account, they need to know one password... and have not only your account passwords for every site, but every username or login name you use for those sites.
@schmid1.079
@schmid1.079 10 ай бұрын
But they would need to get to that password, which is kept by a service specifically made for keeping that one password safe. Its a lot safer than reusing the same password or using insecure ones. If you can remember dozens of complex passwords from memory, sure thats safer. But thats just not how things work in reality.
@Akab
@Akab 10 ай бұрын
Thing is, with a web space and a domain you can get a fully custom invite link for less then 1,50 month
@qjo_maste
@qjo_maste 10 ай бұрын
also witch browser are you using it look cool
@bomboi8222
@bomboi8222 10 ай бұрын
at this point even discord got hacked in discord
@LushDaBush
@LushDaBush 10 ай бұрын
There are times in my life I'm happy i didn't scoop around stuff like this (my dad's pc survived me trying to download free minecraft over the course of half a decade)
@xE92vD
@xE92vD 10 ай бұрын
Once passkeys are supported in Discord, these scams should be no longer effective.
@hbubli
@hbubli 10 ай бұрын
About the single email for every thing, theres still more nerdiness than cloudflare email routing. Running a selfhosted email server and then creating aliases there (definitely did not do that nope no way ;) )
@jordanwardle11
@jordanwardle11 10 ай бұрын
just an fyi, a data breach is a case of when and not if. plus, you will only know about it only if the company decides to reveal it. assume that EVERYTHING is breached
@ZellieOwO
@ZellieOwO 10 ай бұрын
careful with breachforums, those guys are nuts lol
@jayster3.0
@jayster3.0 10 ай бұрын
You sound like the guy from the KZfaq channel CinemaSins, lmao.
@klier8737
@klier8737 10 ай бұрын
you cant reverse engineer a hashing algorithm practically, technically yes but its extremely difficult and time consuming, they would rather bruteforce the hash and try every combination and check if the two hashes match
@denis2381
@denis2381 10 ай бұрын
Today yes, in future? I don't think so
@klier8737
@klier8737 10 ай бұрын
@@denis2381 that is true, hardware is getting more powerful and powerful and quandtum computing is a big deal for cryptography but a lot of algorithms are being made now to be extra secure
@madara2887
@madara2887 10 ай бұрын
What browser is that? The tabs look cool
@Davide0033
@Davide0033 10 ай бұрын
to be fair, if they aren't using some preistoric hashing system brute force is a quite dumb way to steal a password.
@ManBananaCat
@ManBananaCat 10 ай бұрын
2:53 i was really expecting an ad there
@cool_clipzz
@cool_clipzz 10 ай бұрын
Thank you for warning us. LEGEND.
@Woutundra2
@Woutundra2 10 ай бұрын
this is the prime reason why i use discord as is because i sure as hell don't want people getting my private info cuz every single time something goes to shit with it
@denis2381
@denis2381 10 ай бұрын
Example?
@gir0fa
@gir0fa 10 ай бұрын
LOVE THE CONTENT ❤❤
@veronicarodrigues236
@veronicarodrigues236 10 ай бұрын
Me who doesn't know this existed 💀 Thanks for the information
@began2
@began2 10 ай бұрын
That was impressive but it was just protesting discord
@jinnipers.3931
@jinnipers.3931 10 ай бұрын
and doing a horrible job at it as well
@ToughFighterGuy
@ToughFighterGuy 10 ай бұрын
Definitely, I 100% agree with this thought out logic.
@pipo0730
@pipo0730 10 ай бұрын
Can you do a video on the schlatt community discord one of the most toxic servers i know
@aryantiwari7105
@aryantiwari7105 10 ай бұрын
I have cloudfare email routing setup, all i can say is its perfect and fairly easy to set up
@CrysisVN
@CrysisVN 10 ай бұрын
so many good advice on here
@sspiderlily_
@sspiderlily_ 10 ай бұрын
Ah. , you did the idea! nice job.
@ari_archer
@ari_archer 2 ай бұрын
02:50 No. They cannot figure out the original password - all hashing functions are made "equal" (as in all of them are one-way functions which are theoretically impossible to reverse, if you need a two-way function - look into cryptographic algorithms such as AES (most likely in GCM mode for passwords), RSA, ChaCha20, etc.). What makes a hashing function "insecure" are mainly collision attacks (basically two differing inputs producing the same hash, due to for example insecure computation or a small hash size) and "rainbow table attacks" (which in this case isn't well applicable because it was salted, which means the output of the hashing function output is completely different, and I assume dio used at least like a 32 byte salt (256 bits), which should be enough for most cases to avoid the pre-computation attacks) which is just like an index of pre-hashed common inputs. And I doubt dio was using an "insecure" hashing algorithm like MD5, it was most likely some SHA2 (or SHA3)-family algorithms (such as SHA256, SHA512, SHA3-512, ...), or if dio was smart - Argon2. Furthermore, although I know things about cryptography and hashing, I don't know anything about dio, but I assume they have TOTP/2FA, and if they do - I truly hope its users were aware enough to set it up in time. I wouldn't call this an extremely sensitive data breach, but it is uncanny, and the fact that s small portion of users got some of their billing address leaked is sad, considering that identifiable information such as their discord username and email addresses got leaked with it. All this could lead to pretty nasty stalking cases, doxxing, and spear phishing attacks :/
@Refreezerator
@Refreezerator 10 ай бұрын
well, can’t wait to get spam emails now!
@TomerGamerTV
@TomerGamerTV 10 ай бұрын
Good password manager recommendations
@gummyboiyt
@gummyboiyt 10 ай бұрын
Damn bro, a data breach on my birthday.
@thienviet3429
@thienviet3429 10 ай бұрын
For e-mail address: Just use an alias. If they spam, then delete your alias.
@fadefun6728
@fadefun6728 10 ай бұрын
Are you telling someone from breach forms a? used a sequel? vulnerable. because I'm pretty sure they're using my SQL for their database.
@KleinerKokiri
@KleinerKokiri 10 ай бұрын
That hacker sounds like he is projecting.
@NKillBruh
@NKillBruh 10 ай бұрын
I wonder if it has been added to HIBP's database.
@hi-kt3qr
@hi-kt3qr 10 ай бұрын
unlikely they need to get their hands on the database first
@AkaneEndespeakdevReal
@AkaneEndespeakdevReal 10 ай бұрын
Firefox relay is good if you don’t want to use apple or Dont have a domain
@AzaleaTFG
@AzaleaTFG 10 ай бұрын
even for my first name last name i have three emails for school, work, and personal (local) stuff
@WildFyr
@WildFyr 10 ай бұрын
"enable 2fa" Discord makes want to turn it off because as someoke who makes bots i hate the fact that i need to enter a 2FA code not only log into the developer portal, but also need to enter it again to generate a bot token (because they no longer let you see it after you create the bot for some reason, you habe to regen it) and same for the client secret... Like Discord i just created the bot let me see this stuff. Thats 3 times i had to enter a 2FA code all to do the same thing
@SilverBulletKR
@SilverBulletKR 10 ай бұрын
problem with gmail is that you can only make a certain amount of emails with 1 single phone number. And every gmail requires a phone number each which is annoying
@zmoguszmogus7257
@zmoguszmogus7257 10 ай бұрын
not really, sometimes u dont need a number
@SilverBulletKR
@SilverBulletKR 10 ай бұрын
@@zmoguszmogus7257 teach pls
@pinkhairsimp
@pinkhairsimp 10 ай бұрын
best thing to see on my yt recommended
@Axel_Kasai
@Axel_Kasai 10 ай бұрын
But does this affect actual discord? Like what happened with g+ getting sued because of a data breach?
@TeamGalactic-Cyrus
@TeamGalactic-Cyrus 10 ай бұрын
no
@mmkanashiro
@mmkanashiro 10 ай бұрын
4:36 the guy watching the video be like: well... im fucked
@zhabiboss
@zhabiboss 10 ай бұрын
I didn’t even know this existed.
@That_Puppet
@That_Puppet 10 ай бұрын
1:09 i heard that smoke alarm beep
@pzyko21
@pzyko21 10 ай бұрын
to the 2fa "this will protect your account if you use the same password for everything" is only partially right, if your email ALSO uses that PW and has no own 2fa, it can be disabled within a jiffy. so remember², also put on 2fa on your email.
@OneAndOnlyZekePolaris
@OneAndOnlyZekePolaris 10 ай бұрын
That site doesn't use money btw. They use credits.
@rijaja
@rijaja 10 ай бұрын
"Discord is full of creeps" lmao like 99% of the students at my school are on our discord server. I think the collateral damage is a bit high on this one. If "getting revenge on creeps" was the goal, that is.
@moneycat105
@moneycat105 10 ай бұрын
I use apples contacts app as a password manager.
@umbreonben
@umbreonben 10 ай бұрын
Dudes sounding like AsianHalfSquat and Valiksbum at the same time
@casual_Ign
@casual_Ign 10 ай бұрын
Thankfully i I’m too lazy to do this stuff so i wasn’t apart of this data breach
@LDTV22OfficialChannel
@LDTV22OfficialChannel 10 ай бұрын
If it's old, you don't need to worry. He still won't make money off the breach anyways.
@RPM12534
@RPM12534 10 ай бұрын
this isnt a discord data breach right? like if you dont use discord io your safe?
@hoteny
@hoteny 10 ай бұрын
8th day of me waiting a reply to my ticket from discord’s indian tech support…
@YeensWrath
@YeensWrath 10 ай бұрын
A good trick.. is to write down your password on a piece of paper and hide it somewhere only you know where to find them. This way, you keep track of multiple passwords without needing to rely on 3rd party websites
@anomaly_echelon7994
@anomaly_echelon7994 10 ай бұрын
if that's the case, someone you know irl can have access to all your accounts if they get hold of the piece of paper and if you don't back up that data to other piece of paper and you loose it, you loose access to your accounts. I'd say use a open source password manager and try to back up it's data and save it in a few encrypted USB flash drives where only you know the password to the decryption key.
@Muffiz_
@Muffiz_ 10 ай бұрын
ntts is always entertaining somehow
@FinnishEmpire
@FinnishEmpire 10 ай бұрын
8:24 bro actually said that 💀
Discord Users Got Randomly Banned!
10:26
No Text To Speech
Рет қаралды 714 М.
Discord is Making My (Pathetic) Life Easier!
6:42
No Text To Speech
Рет қаралды 311 М.
🌊Насколько Глубокий Океан ? #shorts
00:42
Alat Seru Penolong untuk Mimpi Indah Bayi!
00:31
Let's GLOW! Indonesian
Рет қаралды 14 МЛН
Did you believe it was real? #tiktok
00:25
Анастасия Тарасова
Рет қаралды 22 МЛН
Re: Housing Development Corporation Ltd (ICOM-C/2023/283)
24:39
Information Commissioner's Office - Maldives
Рет қаралды 10
I've never seen ANYTHING like this before... Temple OS
17:57
Linus Tech Tips
Рет қаралды 4,1 МЛН
How I Made A BETTER & FREE Version Of Rythm On Discord
12:47
ZyberWolfi
Рет қаралды 1,7 М.
Your Discord Messages Are For Sale (4 Billion of Them)
10:29
Seytonic
Рет қаралды 78 М.
You just got Doxxed!
10:33
No Text To Speech
Рет қаралды 729 М.
This town throws pennies at people. They hurt.
5:30
Tom Scott
Рет қаралды 2,2 МЛН
YouTube is Stopping Roblox Scammers?
8:45
No Text To Speech
Рет қаралды 293 М.
Linux HATES Me - Daily Driver Challenge Pt.1
21:02
Linus Tech Tips
Рет қаралды 3,7 МЛН
This Bookmark Can Hack You!
8:04
No Text To Speech
Рет қаралды 1,1 МЛН
Мой инст: denkiselef. Как забрать телефон через экран.
0:54
Blue Mobile 📲 Best For Long Audio Call 📞 💙
0:41
Tech Official
Рет қаралды 1 МЛН
cute mini iphone
0:34
승비니 Seungbini
Рет қаралды 6 МЛН