{"id":5010,"date":"2019-02-25T00:01:04","date_gmt":"2019-02-25T06:01:04","guid":{"rendered":"http:\/\/blog.zoha-islands.com\/?p=5010"},"modified":"2019-02-25T00:01:04","modified_gmt":"2019-02-25T06:01:04","slug":"do-it-now-google-password-checkup","status":"publish","type":"post","link":"https:\/\/zoha-islands.com\/blog\/do-it-now-google-password-checkup\/","title":{"rendered":"[DO IT NOW] Google Password Checkup"},"content":{"rendered":"<p>&nbsp;<\/p>\n<table border=\"0\" width=\"100%\">\n<tbody>\n<tr>\n<td valign=\"top\">\n<div class=\"intro\">\n<p>I thought it would be a good idea to share this post I read about Google Password check. A new Chrome browser extension from Google will alert you if the username and password you are about to enter on a website have been compromised. The Password Checkup extension checks your credentials against a database of four billion login credentials that Google knows have been compromised. I recommend that you give it a try, read on to learn the details&#8230;<\/p>\n<\/div>\n<\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div id=\"adsense-new\"><\/div>\n<div id=\"a005448more\">\n<div id=\"more\">\n<div class=\"KonaBody\">\n<h2>What is the Password Checkup Extension?<\/h2>\n<p><a href=\"https:\/\/chrome.google.com\/webstore\/detail\/password-checkup\/pncabnpcffmalkkjpajodfhijclecjno\" target=\"_blank\" rel=\"noopener noreferrer\">Password Checkup<\/a> is an optional add-on for the Google Chrome browser that helps you identify online accounts that have been affected by data breaches. If you&#8217;re not familiar with the term, a data breach occurs when hackers break into a poorly secured website, and steal personal information stored there. Unfortunately, this happens with alarming regularity, and can impact tens of millions of users, revealing some combination of names, addresses, phone numbers, social security numbers, birth dates, driver&#8217;s license data, and of course usernames and passwords. That data is bundled up and sold on various black markets online.<img decoding=\"async\" loading=\"lazy\" class=\"alignleft wp-image-5019\" src=\"http:\/\/blog.zoha-islands.com\/wp-content\/uploads\/2019\/02\/Databreach-300x162.jpg\" alt=\"\" width=\"481\" height=\"260\" srcset=\"https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2019\/02\/Databreach-300x162.jpg 300w, https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2019\/02\/Databreach.jpg 650w\" sizes=\"(max-width: 481px) 100vw, 481px\" \/><\/p>\n<p><span id=\"ezoic-pub-ad-placeholder-116\" class=\"ezoic-adpicker-ad\"><\/span>Dashlane, which offers a popular password manager, published a list of the <a href=\"https:\/\/blog.dashlane.com\/data-breaches-2018\/\" target=\"_blank\" rel=\"noopener noreferrer\">20 Biggest Data Breaches of 2018<\/a>. Among them are Marriot (500 million records including names, addresses, phone numbers, email addresses, passport numbers, and dates of birth); Exactis (340 million records including names, addresses, email addresses, phone numbers, and other personal information such as habits, hobbies, and the number, ages, and genders of the person\u2019s children; and Twitter (330 million plain-text passwords). Going back to 2017, there was the horrific Equifax breach which affected 143 million Americans, and included names, social security numbers, birthdates, addresses and, in some instances, driver\u2019s license numbers and credit card numbers. And those are just the highlights. If you&#8217;ve done business with Uber, Verizon, Under Armour, Panera Bread, T-Mobile, Saks, or Lord and Taylor, your personal information may be &#8220;out there&#8221;.<span id=\"ezoic-pub-ad-placeholder-111\" class=\"ezoic-adpicker-ad\"><\/span><\/p>\n<p>Wherever you sign-in, if you enter a username and password that is no longer safe due to appearing in a data breach known to Google, you\u2019ll receive an alert. Please reset your password. If you use the same username and password for any other accounts, please reset your password there as well.<\/p>\n<p>If you get an alert, you should change your password right away, even though password resets are complicated and time-consuming. When it\u2019s time to choose a new password, let Chrome suggest a strong one; right-click while your cursor is in the password box and select \u201cSuggest strong password\u201d at the top of the context menu. If you choose to use the suggested password, Chrome will enter it and save it to your passwords list.<\/p>\n<p><span id=\"ezoic-pub-ad-placeholder-112\" class=\"ezoic-adpicker-ad\"><\/span><span id=\"div-gpt-ad-askbobrankin_com-box-4-0\" class=\"ezoic-ad\"><\/span>It\u2019s not clear where Google got its four billion compromised credentials. The company says that it has reset over 110 million Google account passwords in the past two years; presumably, those compromised passwords are in the database. Google doesn&#8217;t say<\/p>\n<p>where the rest come from or how quickly they are added to the database. But my guess is that they keep tabs on the major data breaches and incorporate that information into their service.<span id=\"ezoic-pub-ad-placeholder-117\" class=\"ezoic-adpicker-ad\"><\/span><\/p>\n<p><b>Password Checkup addresses the problem of password re-use.<\/b> If you follow the best practice of using a unique password on every site, you only have to reset one site\u2019s password if your password is compromised. But if you have re-used a password on multiple sites, you probably don\u2019t recall which ones need to be reset. Password Checkup will alert you each time you try to use compromised credentials. So it is of great use in plugging the very common password re-use vulnerability.<\/p>\n<p>Google is not the first to market with a password checker. For nearly a year, the <a href=\"https:\/\/blog.1password.com\/finding-pwned-passwords-with-1password\/\" target=\"_blank\" rel=\"noopener noreferrer\">1Password password manager<\/a> has integrated with Troy Hunt\u2019s Pwned Passwords database, which currently contains about half a billion compromised credentials.<\/p>\n<p>Unlike Google, 1Password downloads all of the compromised credentials to each user\u2019s machine. While this avoids uploading a user\u2019s credentials to 1Password\u2019s server, it puts an ever-growing burden on the user\u2019s computing resources. Google, instead, works in the cloud with encrypted copies of user data, so Google never knows what the user\u2019s credentials are. Google\u2019s password manager is free, while 1Password costs about $3 per month for a single user.<\/p>\n<p><span id=\"ezoic-pub-ad-placeholder-113\" class=\"ezoic-adpicker-ad\"><\/span><b>Google addresses the privacy issue of Password Checker thusly:<\/b> &#8220;Password Checkup was built with privacy in mind. It never reports any identifying information about your accounts, passwords, or device. We do report anonymous information about the number of lookups that surface an unsafe credential, whether an alert leads to a password change, and the domain involved for improving site coverage.&#8221; You can learn more about <a href=\"https:\/\/support.google.com\/accounts?p=password-checkup\" target=\"_blank\" rel=\"noopener noreferrer\">how Password Checkup works<\/a>.<\/p>\n<p>This is the first public release of Password Checkup; even Google admits there\u2019s room for improvement in the future. Making it work with more log-in screen formats is a high priority. I would like the extension to check all of my saved passwords in one batch and show me which ones need to be changed. Some automation of tedious password-reset routines would also be very welcome.<\/p>\n<p><b>But what would really make my day is the elimination of passwords altogether.<\/b> I long for the day when bio metric or hardware key security becomes the universal norm. Then we will have much less to remember, maintain, and worry about. A lot of progress has been made on the mobile device side, with fingerprint, voice and face identification options.<\/p>\n<p>Have you checked to see if your email addresses and\/or passwords have been compromised?<\/p>\n<p>Thanks to Bob for this post as always<\/p>\n<p>From all of us on the ZI Staff have a great week.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; I thought it would be a good idea to share this post I read about Google Password check. A new Chrome browser extension from Google will alert you if the username and password you are about to enter on a website have been compromised. The Password Checkup extension checks your credentials against a database &hellip; <a href=\"https:\/\/zoha-islands.com\/blog\/do-it-now-google-password-checkup\/\" class=\"more-link\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":5018,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,3,4,5,6],"tags":[],"_links":{"self":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts\/5010"}],"collection":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/comments?post=5010"}],"version-history":[{"count":0,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts\/5010\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/media\/5018"}],"wp:attachment":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/media?parent=5010"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/categories?post=5010"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/tags?post=5010"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}