NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business / Companies / Telecommunications

Juha Saarinen: My password is... and Spark revisited

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
15 Sep, 2014 12:08 AM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Email security is in the spotlight again after another mass hacking scare saw millions of Gmail account credentials posted on the internet. Photo / Thinkstock

Email security is in the spotlight again after another mass hacking scare saw millions of Gmail account credentials posted on the internet. Photo / Thinkstock

Juha Saarinen
Opinion by Juha Saarinen
Tech writer for NZ Herald.
Learn more

Last week we learnt that someone had casually posted a huge amount of user logins for Gmail, namely just under five million email addresses and passwords.

A staggering amount but luckily, most appear not to work as the data dump was collected from a variety of sources and isn't the freshest one.

Google said that it didn't come from them and what active accounts they've been able to spot have been protected and a password reset being enforced.

Either way, if you haven't changed your passwords for a while, or use the same one across several services, now's a good time to fix that. While I'm cautious about telling anyone to enter any part of their credentials on third-party site, this website is a handy tool to check if your email address has ended up in a data dump somewhere on the internet.

haveibeenpwned ("pwned" being 1337-speak for owned, or captured) does not store passwords; the point of the volunteer site is to tell people if their accounts have been compromised, nothing else.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Now, it's worth noting that the figure of leaked accounts continues to grow at a frankly alarming rate. Last week, the number was around 166 million compromised accounts on haveibeenpwned.

As of writing a few days later, we're now up to a grand total of 174,451,409 accounts. The figure includes the "mother of all data breaches" namely the Adobe one that saw over 152 million accounts leak out on the Internet.

That total number above is actually on the low side because haveibeenpwned.com does not include several millions of other accounts that weren't publicly released, from LinkedIn, Evernote, Kickstarter and Target to mention a few sites and organisations that have suffered data breaches.

Those accounts would add something like 182 million credentials to the tally. These are colossal numbers so I asked software architect and Microsoft valued professional (MVP) Troy Hunt in Australia who runs the ihavebeenpwned site how much space it all takes.
Troy said that the millions of records don't actually take up much space in modern data volume terms - only around 15 gigabytes.

This is stored uncompressed in Microsoft's cloud platform using Azure Storage and Troy's written about how he did it last year.

Discover more

Opinion

Juha Saarinen: C-Level technocrats? No thanks

17 Jul 11:54 PM
Opinion

Juha Saarinen: Knocking off Nokia

23 Jul 01:57 AM
Opinion

Juha Saarinen: Telecom vs Chorus

25 Jul 12:22 AM
Opinion

Juha Saarinen: Aussies clamp down on dastardly downloaders

30 Jul 12:00 AM

With that many credentials on one site and haveibeenpwned being rather fast in searching them, I asked Troy if there's a risk that the service could be abused by hackers to validate email addresses - and yes, it could he said.

"However, if I was "Mr Attacker", I'd go and just grab the original dump of data - they're all public - and enumerate through that locally rather than making all those slow, unnecessary HTTP requests," Troy said.

Advertisement
Advertise with NZME.

I also asked Troy if the colossal number of leaked credentials meant that having your email address as the username is a bad idea.

He disagreed and said that you still need an email address for password resets, meaning the two are rather intrinsically linked.

"The bigger challenge is credential reuse and weak passwords which goes to the previous point on password managers," Troy said.

That said, everything needs a logon these days and it's quite frankly unmanageable to make up long and secure ones for each and every site and hope to remember them.
What's the answer then?

Use a password manager. These will let you create really long and impossible to guess passwords, unique for each site.

A good password manager will also audit your existing set of passwords to ensure they're good and strong, and warn about old ones.

Advertisement
Advertise with NZME.

"The only secure password is the one you can't remember" as Troy puts it. Yep, as long as your password manager can though.

The Spark outage revisited

Right, I've had quite a number of people asking what actually happened during the massive Spark internet outage. Was it masses of frenzied hordes of Spark customers clicking on malware-linked stolen pics of J-Law or something else?

Read more:
• Spark users experience internet meltdown
• Juha Saarinen: XT time all over again?

Spark sent out a post-mortem message some days ago, but there were still a few unclear areas so I asked for clarification; here's summary of events chronologically that I hope is useful, based on Spark's official answers.

1) On Friday at 8pm unknown digital miscreants that had found open DNS resolvers on 138 modems belonging to Spark customers started a series of distributed denial of service (DDoS) attacks that lasted through to early Sunday morning that weekend.

According to Spark, the attacks came in waves, and changed in scale and nature over time. Actions were taken to prevent any risk of further exposure, Spark said - see below.

Advertisement
Advertise with NZME.

2) Spark's understanding is that the hackers started sending queries through the open resolvers for the purpose of DNS amplification attacks that create large amounts of traffic.

3) These queries were directed through the Spark Domain Name System servers, the ones that translate numeric addresses like 8.8.4.4 to some.internet.address.co.nz.

4) The queries appeared to come from a variety of locations around the world, some of which may have been forged by the attackers. However, the destination domains for the attacks were in Eastern Europe, Spark said.

5) As a large number of queries hit Spark's DNS servers, they became swamped while trying to resolve (translate) and respond to these.

6) To fix the problem, Spark blocked incoming traffic on port 53 UDP, as used for DNS queries.

7) Spark also disconnected some customer modems and blocked access to the open resolvers.

Advertisement
Advertise with NZME.

The fixes along with the hackers ceasing the attack meant that things went back to normal, eventually, on Sunday and Monday.

No malware has been found on customer devices as of yet, but Spark told me it hasn't ruled it out.

There's one big question left however: vulnerable broadband modems, old and new ones. What to do with them? Obviously, if these can be abused, another attack could take place.

In many cases, modem vendors will never issue security updates for modems, so would Spark consider perhaps a trade-in programme for these to ensure that customers and the provider's network remains secure?

"Considering best options at the moment," was the answer from Spark.

Save

    Share this article

Latest from Telecommunications

Business|companies

One NZ expands Starlink partnership to Internet of Things

15 Jun 09:34 PM
Premium
Stock takes

Stock Takes: Why NZ's largest firms are suddenly ripe for takeover talks

12 Jun 09:00 PM
Premium
Technology

Tech Insider: A $529 phone, bought in March, can only make 3G calls; IRD’s AI warning; Musk’s pain is Beck’s gain; a self-employed Wellington man scores a $16K Google Cloud refund

10 Jun 03:14 AM

Jono and Ben brew up a tea-fuelled adventure in Sri Lanka

sponsored
Advertisement
Advertise with NZME.

Latest from Telecommunications

One NZ expands Starlink partnership to Internet of Things

One NZ expands Starlink partnership to Internet of Things

15 Jun 09:34 PM

Direct to Cell service reaches 40% of the country not covered by land-based networks.

Premium
Stock Takes: Why NZ's largest firms are suddenly ripe for takeover talks

Stock Takes: Why NZ's largest firms are suddenly ripe for takeover talks

12 Jun 09:00 PM
Premium
Tech Insider: A $529 phone, bought in March, can only make 3G calls; IRD’s AI warning; Musk’s pain is Beck’s gain; a self-employed Wellington man scores a $16K Google Cloud refund

Tech Insider: A $529 phone, bought in March, can only make 3G calls; IRD’s AI warning; Musk’s pain is Beck’s gain; a self-employed Wellington man scores a $16K Google Cloud refund

10 Jun 03:14 AM
All the iOS 26 changes and new updates for your Apple devices from WWDC

All the iOS 26 changes and new updates for your Apple devices from WWDC

09 Jun 10:28 PM
Help for those helping hardest-hit
sponsored

Help for those helping hardest-hit

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP