5 ms·
This title is incorrect. Credentials not stolen, usernames and hashed passwords stolen. That is not the same as having everyone's password. The title implies
by dpweb 10y ago
This title is incorrect. Credentials not stolen, usernames and hashed passwords stolen. That is not the same as having everyone's password. The title implies someone can easily log in to your account.
- user5994461 10y ago> That is not the same as having everyone's password It is for everyone who used "weebly" or any of the top 100 most common passwords. That could mean no less than 82% of users are at risk.
- jorisvansoest 10y agomore than 63% of all statistics are made up [1] [1] me
- novaleaf 10y agoThis is also not true, as if they used bcrypt (a key derivation function) the hash is salted, so even users using common passwords are protected against rainbow (lookup table) attacks. as for brute force, yes attackers now know usernames, so can try brute forcing the live sites, or brute forcing each user hash.
- MasterScrat 10y agoI believe he meant the will try the top 100 most common passwords on each account on the website directly, resulting on "82% of users at risk", assuming 82% of users use one of these 100 passwords. Strong brute-force protection (eg block account for exponential times) could mitigate this attack vector.
- user5994461 10y agoWhy are you guys talking about live site and rainbow table??? The attackers have the salts and the hashes, they can brute force the hashes offline with [ocl]hashcat as they wish. Top 100 passwords * 43M accounts is only ~4B hashes to compute. We don't know what bcrypt parameters they used but we're probably talking a few hours here, maybe only a few minutes.
- novaleaf 10y agoto brute force the top 100 passwords, only the usernames were really required. can easily bruteforce the top 100 passwords on a live site. you are right that it's now very easy to use dictionary attacks now, on all the credentials offline. and those with super weak passwords will have their accounts compromised.