5 ms·
Seems like most spammers / scammers are finding out passwords of old accounts instead of creating new ones (which are a pain to create due to the phone number v
by aboutruby 8y ago
Seems like most spammers / scammers are finding out passwords of old accounts instead of creating new ones (which are a pain to create due to the phone number verification and the disposable phone numbers ban).
Twitter should probably scan their user passwords for obvious / most-used ones and require their users to change their passwords.
- overcast 8y agoAssuming they aren't using plain text, or simple hashes, how would Twitter do that? Even a standard salted password against that many accounts is tens of millions of cpu hours. Using something like bcrypt would be 10,000x slower than that!
- michaelbuckbee 8y agoHonestly, the easiest thing to do would be to force a password change on any user that hadn't logged in in X months.
- darkmarmot 8y agoSince they have the salts, they could just take a common passwords list, generate the hashes associated with all of them, then force any users with matching hashes to change their passwords.
- overcast 8y agoYou're misunderstanding how this would work. This is effectively what a hacker would do brute force. You have to generate a hash for each password in your common list, for EACH salt in your user list. 326 million Twitter users x each password in your list. Really comes down to which hashing function they chose, and how fast it does that calculation. Something like bcrypt is roughly 100ms per hash, which is a LONG time when you're crunching billions of them.
- llukas 8y agoFor 10k passwords and 100ms per hash it is 90 hours of single threaded execution time. There is no excuse not to do it, especially you need to do it only once per user (until password change).
- giancarlostoro 8y agoAs somebody else commented, a quicker solution is to just force a password reset based on number of months since last login. If you havent logged in for over a year is a good rule of thumb.
- overcast 8y agoRight, but I was replying to OP. "Twitter should probably scan their user passwords for obvious / most-used ones and require their users to change their passwords."
- kgermino 8y ago>For 10k passwords and 100ms per hash it is 90 hours of single threaded execution time. That's 90 hours per account, multiply that by 326 million accounts and it's over a billion CPU days. You can reduce it a lot (no need to spend time calculating the password for users who log in regularly, just wait for them to give it to you) but it's still a massive scale. Especially since the biggest risk comes from the millions of rarely used accounts.
- llukas 8y agoCorrect. Forgot to multiply by 10^6
- justsomedood 8y agoI'm getting 90 million hours of single threaded execution time for 326 million users with 10k passwords each, and 100ms per hash.
- dasil003 8y ago
- deleted 8y ago[deleted]
- aboutruby 8y agoI mean, the account stealers can do it, and not Twitter itself? Which one has the most ressources?
- sigfubar 8y agoForce every single user to change their password right now. When a new password is entered, check it against common passwords, and reject bad inputs as needed.
- ElijahLynn 8y agoThis would cause friction and they would lose users, which would piss off investors. This isn't a technical issue.
- sigfubar 8y agoConsidering the degree to which most Twitter users are trash, I wouldn't mind losing a few of those. The rest will understand the need for security.
- penagwin 8y agoYeah but you're not an investor. Twitters been struggling to make money for a long time, do you think the investors would be happy to see a decline in active users because of "security" - a concept they barely understand?
- sigfubar 8y agoI’m not an investor in Twitter because I don’t invest in companies that are unable to assume an appropriate security posture. The same reasoning leads one to conclude that dilettantes who do hold Twitter stock deserve to get burned when poor security practices come home to roost.