Microsoft has confirmed that thousands of Windows Live accounts have been compromised with their passwords posted online. Mainstream media such as the BBC are also carrying the story. Some information is posted here.
UPDATE: Gmail and Yahoo are also affected by the compromise. Change all passwords on any of these popular webmail sites.
Some does and don'ts:
Cheers,
Adrien de Beaupré
EWA-Canada.com
I know that tools for this purpose have existed for some time, but I only now realise the real necessity of them.
It would be so much easier if we were using public-key crypto for everything now, but passwords are still with us. Fortunately, the keychain idea makes it no longer difficult to use very long passwords with a great deal of entropy, which can be changed with much less of a burden; almost to the point of being a cryptographic 'nonce' used for authentication.