4 ms·
Cracking My Own Reddit Password
- snek 9y agomfw already posted like two weeks ago
- ColinWright 9y agoYou're too optimistic: https://news.ycombinator.com/item?id=14108223 https://news.ycombinator.com/item?id=14108223 (17 days) https://news.ycombinator.com/item?id=14076918 https://news.ycombinator.com/item?id=14076918 (20 days) https://news.ycombinator.com/item?id=14071188 https://news.ycombinator.com/item?id=14071188 (21 days) https://news.ycombinator.com/item?id=14054289 https://news.ycombinator.com/item?id=14054289 (23 days) https://news.ycombinator.com/item?id=14051671 https://news.ycombinator.com/item?id=14051671 (24 days) None have any comments, very few upvotes, so maybe it's worth another chance. Personally, I found it unreadable. I'm sure others will find it fascinating and be able to get past the IN YOUR FACE style and flashing graphics. Oh, and FWIW, I didn't downvote you.
- glubGlub 9y agoAnd it has NOTHING TO DO WITH REDDIT.
- Retr0spectrum 9y agoThis sort of challenge comes up in CTFs quite often. Here's a writeup of one from PicoCTF 2017 (not mine): https://github.com/Caesurus/PicoCTF2017/tree/master/l3_noeyes https://github.com/Caesurus/PicoCTF2017/tree/master/l3_noeye...
- kordless 9y agoConsidering how much effort this took, I'm wondering if learning to be more patient might also be an option?
- deleted 9y ago[deleted]
- jedberg 9y agoClickbait title much? This basically has nothing at all to do with reddit. You could replace the word reddit with Facebook in this article and it would be exactly the same. That being said, it was pretty clever to take advantage of an enumeration attack on another service that wasn't protecting against enumeration attacks on the feature because frankly, why would they?
- wand3r 9y ago> click bait title No. I went in expecting it to be about a guy who lost his own password to Reddit and had to crack it. Spoiler: That's what the article was about.
- et-al 9y agoHe hardly cracked his password. He played Hangman. I would hope there's no service out there that lets you guess passwords like this. "Is there an F in your password? Yes, you have one F, now guess again..."
- morganvachon 9y ago> I would hope there's no service out there that lets you guess passwords like this. Technically he didn't guess the password to any specific service, he just happened to have stored his own Reddit password in plaintext as the body of a draft email. The email service allows you to search within the body even if your message is "hidden" from their interface. At worst, he MacGyvered a feature of their service to recover a string he couldn't remember. This was a coding exercise, nothing more. If he had stored his Reddit password in some obfuscated/encrypted format behind another password-protected service, he likely would not have pulled off this stunt.
- letter_me_later 9y agoUh. No. The article is a subversive ad for http://lettermelater.com http://lettermelater.com and little more.
- jedberg 9y ago
- stu-harvey 9y agoWorking link: https://medium.freecodecamp.com/the-time-i-had-to-crack-my-own-reddit-password-a6077c0a13b4 https://medium.freecodecamp.com/the-time-i-had-to-crack-my-o...
- m0atz 9y agoThis literally is fucking awesome.
- rocqua 9y agoIt seems like an interesting complication here comes from the subject line. I idly wonder how to handle the case where the subject line had been much larger and had much overlap with the password.
- hiisukun 9y agoPerhaps because I'm new to this stuff, I enjoyed the writeup. I wonder if I'm out of place expecting a single run through of a-z 0-9 to determine the range of chars present in the password? It turns out (due to repeated chars) to only have 14 unique chars. This single run through would have reduced the alphabet size (A, in the article) from 36 to 14. The 432 iterations becomes 168. I'm sure there are other optimisations I'm missing!