You may have seen in the news that the site that provides the icons/images for this site and other WordPress based sites has been involved in a breach
[See the full post at: Gravatar data leak]
Susan Bradley Patch Lady/Prudent patcher
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
Home » Forums » Newsletter and Homepage topics » Gravatar data leak
Tags: Patch Lady Posts
You may have seen in the news that the site that provides the icons/images for this site and other WordPress based sites has been involved in a breach
[See the full post at: Gravatar data leak]
Susan Bradley Patch Lady/Prudent patcher
There’s something more going on with this data. I got a notice from Troy Hunt’s Have I Been Pwned that an address of mine that I only use for personal communication (never for any kind of business) was in the data set. I had never even heard of this company until now and confirmed that I’ve never signed up for anything with them or even received an email from them. The address is in the form of firstname@firstnamelastname.com so they might have created a spam list of some kind that they never used, but it definitely didn’t come from me.
The last bit of advice about changing all the passwords periodically is a bit tough in practice. I have 336 passwords in my Keepass database. Early in the lock down I went through all of them to ensure they are all unique and complex, but it took me forever. I don’t think I could do that often, even if I could find the time to do so.
Chris
Win 10 Pro x64 Group A
I also use KeePass and have hundreds of entries. To be able to check all my passwords at once (saving me a ton of time!), I added a plugin called HIBPOfflineCheck that checks your passwords against the Have I Been Pwnd breach data. It can either do an online check or an offline check. To do an offline check you’ll need to download a large file from HIBP’s site. It’s faster – and I think more secure – than the online check so that’s what I use. I check monthly to see if a new breach file is available for download. After downloading, clear the previous check in KeePass using the entry under the “Tools” dropdown menu and run another check against the new data file. Takes no time at all.
https://keepass.info/plugins.html#breachchk
https://github.com/mihaifm/HIBPOfflineCheck
https://haveibeenpwned.com/Passwords (scroll to the bottom of the page and download the “SHA-1 by hash” version)
Win10 Pro x64 22H2, Win10 Home 22H2, Linux Mint + a cat with 'tortitude'.
Woody published a blog warning about disclosing personal info into Gravatar in October 2020:
https://www.askwoody.com/2020/if-you-have-an-avatar-a-picture-here-on-askwoody-make-sure-gravatar-doesnt-have-any-personal-data/
‘Da Boss’ with finger on the pulse as usual..
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.
Notifications