link1s.site

The largest password leak in history exposes nearly 10 billion credentials

The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews.

This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords.

Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum.

“In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.”

Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems.

Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said.

This could affect online services, cameras and hardware

This could affect various targets, from online services to internet-facing cameras and industrial hardware.

“Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded.

However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades.

This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak.

Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information.

That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms.

Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security.

Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.

Google may bring Google Wallet for Indian users
Google Wallet can help you store your IDs, driving license, loyalty cards, concert tickets and more. You can also store your payment cards and use tap to pay to pay anywhere Google Pay is accepted. Google wallet is available in various countries but Google never launched it in India. Google let indian users stick with the Gpay which facilitates UPI payments. Tap to pay is not part of it. Also we can not store things such as IDs and Passes in indian version of Gpay. This might change and Google may launch Google Wallet in India. With the recent version of Google Wallet and Google Play Services, Google has added some flags and code which indicate that Google is working on something for Indian users regarding wallet. The first change I noticed recently when going through the Google Play Services apk was addition of two new flags Both flags are part of com.google.android.gms.pay package in the Google Play Services. This package contains all the flags for features of Gpay/Wallet. Google does server side flipping of flags to enable/disable features for users. So both these flags doesn't really provide any info about what features enabling these flags is going to bring. But the point here is that Google Wallet is not launched in India so why Google added these flags inside Play Services ? The answer could be that Google may be working on bringing Google Wallet to India. It can enable tap to pay, store payments and various other features for Indian users which we don't have in the current Gpay for India. I found similar flags in the analysis Google Wallet APK - These flags are also disabled by default. But this is again a clear indication of Google working towards something for Indian users. In both cases, enabling the flags doesn't bring anything noticeable UI or feature because there is nothing much added besides flags. Google has dogfood/testing versions internally, so the code will show up slowly in upcoming versions. The last piece of code I found is also from Google Play Services. In case you don't know, Google was working on Digilocker integration in the Google Files app which was supposed to bring your digital document inside the app such as driving license, COVID certificates, aadhar card. But Google has ditched the effort of bringing these features and they removed the "Important" tab (where digilocker was supposed to be integrated) from the Google Files app completely. So things are going to change and here is how. This is the code which I found in the Google Play Services - So the word "PASS" along with PAN, DRIVERS LICENCE, VACC CERTIFICATE & AADHAR CARD, is clear indication of the possibility of Google adding support for these directly through Google Wallet using Digilocker, just like Samsung Pass does it. This code is not old as I have checked older beta versions of Play Services where this code is not present. Here is a string which was added in a previous beta version a few weeks ago but I completely ignored it because it didn't make any sense without flags and the other code - This addition was surprising because there was nothing regarding digilocker before in the Play Services. In the words "pay_valuable", the "pay" to Wallet/Gpay and "valuable" refers to the things like Passes, loyalty cards and transit cards. Since we are talking about digilocker, these "valuable" are driving license, vaccination certificate, PAN card and Aadhar card which can be store in Google Wallet after digilocker integration. That's all about it. We will know more about it in upcoming app updates or maybe Google can itself annouce something about this.
Wto: Members have more trade promotion measures than restrictions
The latest trade monitor released recently by the World Trade Organization shows that between mid-October 2023 and mid-May 2024, WTO members continued to introduce more trade promotion measures than trade restrictive measures. The WTO said it was an important signal of members' commitment to keep trade flowing amid the current geopolitical uncertainty. According to WTO statistics, during the monitoring period, WTO members adopted 169 trade promotion measures on commodities, more than the 99 trade restrictive measures introduced. Most of the measures are aimed at imports. Commenting on the findings, WTO Director-General Ngozi Okonjo-Iweala said that despite the challenging geopolitical environment, this latest trade monitoring report highlights the resilience of world trade. Even against the backdrop of rising protectionist pressures and signs of economic fragmentation, governments around the world are taking meaningful steps to liberalize and boost trade. This demonstrates the benefits of trade on people's purchasing power, business competitiveness and price stability. The WTO monitoring also identified significant new developments in economic support measures. Subsidies as part of industrial policy are increasing rapidly, especially in areas related to climate change and national security.
Autonomous driving is not so hot
From the perspective of the two major markets of the United States and China, the autonomous driving industry has fallen into a low tide in recent years. For example, last year, Cruise Origin, one of the twin stars of Silicon Valley autonomous driving companies and once valued at more than $30 billion, failed completely, its Robotaxi (driverless taxi) operation qualification was revoked, and autonomous driving models have been discontinued. However, as a new track with the deep integration of digital economy and real economy, automatic driving is a must answer: on the one hand, automatic driving will accelerate the process of technology commercialization and industrialization, and become an important part of the game of major powers; On the other hand, autonomous driving will also promote industrial transformation and upgrading by improving the mass travel service experience, seeking new engines for urban development, and injecting new vitality into the urban economy.
TikTok to introduce a new feature that can clone your voice with AI in just 10 second
Use of AI is certainly the hottest topic in the tech industry and every major and minor player in this industry is using AI in some way. Tools like ChatGPT can help you do a wide range of task and even help you generate images. The other thing is - Voice Cloning. OpenAI recently introduced a voice engine that can generate clone of your voice with just 15 seconds of your audio. There is no shortage of voice cloning tools on the web which can help you do the same. The newest tech giant which is going to use AI to clone your voice is - TikTok. We all know TikTok, posting short videos with filters, effects and all other kind of things. So TikTok found a way to use the voice cloning AI in its app. TikTok is working on this feature, which does not seem to really have a proper name, it just references it as "Create your voice with AI" and "TikTok Voice Library". In the latest version of TikTok I came across some strings which indicates that TikTok is working on it. I was also able to access the initial UI which introduces the feature and was able to see the terms and condition of "TikTok Voice Library" which user have to accept in order to use the feature. Here are the screenshots from the app- As you can in the screenshot above, this is the initial screen which a user will see for the first time they access this feature. Tiktok claims that it can create an AI verison of your voice in just 10 seconds. The generated AI voice clone can be used with text-to-speech in TikTok videos. It also outline the process of how it will work. You have to record yourself speaking and TikTok will process the voice and use information about your voice to generate your AI voice. When it comes to privacy, your AI voice will stay private and you can delete it anytime. Tapping the "Continue" button brings "TikTok Voice Library Terms" screen which a user should definitely read, you can see here and read as well - How it will work After agreeing to terms and conditions I was introduced with a screen where TikTok will show some text and user have to press the record button while reading the text. Now unfortunately I did not see any text. This is probably because the feature is not fully ready or the backend from which it fetches the text is not live yet. Manually pressing the record button and saying random things also shows an error. So, it's also not possible to provide any sample voice generated with it and see how it compares to other voice cloning competitors. If it starts working someday, it will process your recorded voice and generate AI version of your voice. Here is a screenshot of that screen - My guess is that whenever the feature starts working, users have to clone voice only one time and the saved AI voice can be used through the text-to-speech method to add voice in your videos. You just have to type the words, choice is yours :p
US foreign policy is advanced smartphone with weak battery
A couple of days ago, a Quad summit meeting in Sydney scheduled for May 24 was abruptly canceled. The US president had to pull out of his long-anticipated trip to Australia and Papua New Guinea. Instead, the heads of the four Quad member states got together on the margins of the G7 Summit in Hiroshima on May 20. The main reason for the change of plans was the continuous struggle between the White House and Republicans on the Hill over the national debt ceiling. If no compromise is reached, the US federal government might fail to meet its financial commitments already in June; such a technical default would have multiple negative repercussions for the US, as well as for the global economy and finance at large. Let us hope that a compromise between the two branches of US power will be found and that the ceiling of the national debt will be raised once again. However, this rather awkward last-minute cancellation of the Quad summit reflects a fundamental US problem - a growing imbalance between the US geopolitical ambitions and the fragility of the national financial foundation to serve these ambitions. The Biden administration appears to be fully committed to bringing humankind back to the unipolar world that existed right after the end of the Cold War some 30 years ago, but the White House no longer has enough resources at its disposal to sustain such an undertaking. As they say in America: You cannot not have champagne on a beer budget. The growing gap between the ends that the US seeks in international relations and the means that it has available is particularly striking in the case of the so-called dual containment policy that Washington now pursues toward Russia and China. Even half a century ago, when the US was much stronger in relative terms than it is today, the Nixon administration realized that containing both Moscow and Beijing simultaneously was not a good idea: "Dual containment" would imply prohibitively high economic costs for the US and would result in too many unpredictable political risks. The Nixon administration decided to focus on containing the Soviet Union as the most important US strategic adversary of the time. This is why Henry Kissinger flew to Beijing in July 1971 to arrange the first US-China summit in February 1972 leading to a subsequent rapid rapprochement between the two nations. In the early days of the Biden administration, it seemed that the White House was once again trying to avoid the unattractive "dual containment" option. The White House rushed to extend the New START in January 2021 and held an early US-Russia summit meeting five months later in Geneva. At that point many analysts predicted that Biden would play Henry Kissinger in reverse - that is he would try to peace with the relatively weaker opponent (Moscow) in order to focus on containing the stronger one (Beijing). However, after the beginning of the Russia-Ukraine conflict, it became clear that no accommodation with the Kremlin was on Biden's mind any longer. Still, having decided to take a hard-line stance toward Moscow and to lead a broad Western coalition in providing military and economic assistance to Kiev, Washington has not opted for a more accommodative or at least a more flexible policy toward Beijing. On the contrary, over last year one could observe a continuous hardening of the US' China policy - including granting more political and military support to the Taiwan island, encouraging US allies and partners in Asia to increase their defense spending, engaging in more navel activities in the Pacific and imposing more technology sanctions on China. In the meantime, economic and social problems within the US are mounting. The national debt ceiling is only the tip of an iceberg - the future of the American economy is now clouded by high US Federal Reserve interest rates that slow down growth, feed unemployment and might well lead to a recession. Moreover, the US society remains split along the same lines it was during the presidency of Donald Trump. The Biden administration has clearly failed to reunite America: Many of the social, political, regional, ethnic and even generational divisions have got only deeper since January 2021. It is hard to imagine how a nation divided so deeply and along so many lines could demonstrate continuity and strategic vision in its foreign policy, or to allocate financial resources needed to sustain a visionary and consistent global leadership. Of course, the "dual containment" policy is not the only illustration of the gap between the US ambitions and its resources. The same gap inevitably pops up at every major forum that the US conducts with select groups of countries from the Global South - Africa, Southeast Asia, Latin America or the Middle East. The Biden administration has no shortage of arguments warning these countries about potential perils of cooperating with Moscow or Beijing, but it does not offer too many plausible alternatives that would showcase the US generosity, its strategic vision, and its true commitment to the burning needs of the US interlocutors. To cut it short, Uncle Sam brings lots of sticks to such meetings, but not enough carrots to win the audience. In sum, US foreign policy under President Joe Biden reminds people of a very advanced and highly sophisticated smartphone that has a rather weak battery, which is not really energy efficient. The proud owner of the gadget has to look perennially for a power socket in order not to have the phone running out of power at any inappropriate moment. Maybe the time has come for the smartphone owner to look for another model that would have fewer fancy apps, but a stronger and a more efficient battery, which will make the appliance more convenient and reliable.