4 ms·
Here is the list of Gawker passwords along with MySQL, FTP accounts http://pastebin.com/9rRmf6W5 http://pastebin.com/9rRmf6W5 Thousands of people still use "pa
by netaddict 16y ago
Here is the list of Gawker passwords along with MySQL, FTP accounts http://pastebin.com/9rRmf6W5 http://pastebin.com/9rRmf6W5
Thousands of people still use "password" as their password.
- Qz 16y agoIs this gawker.com only? I have accounts on related sites like kotaku and jezebel, but I don't see any of them in that list.
- netaddict 16y agoTheir entire database was stolen. So you should change your password to be safe.
- tsigo 16y agoThe list on that pastebin is only a sample of what they bothered to crack themselves (easy passwords like "password" and "qwerty"). The torrent posted in another comment contains the entire database.
- yuhong 16y agoAnd if you read that file, you will read that they used DES for hashing. Reminds me of the LM hash. The LM hash generated two hashes using DES from two 7 byte parts of a 14 byte password. Basically they use each individual 7 byte part as a DES key to encrypt a fixed string. Repeat this twice for each 7 byte part, and concatenate the results, and you get the LM hash.
- LiveTheDream 16y agoHow many people really care about the security of their Gawker account though? They just want comment on a blog post; in order to do that, they must remember a password. "password" achieves that admirably. Now, if they are using "password" as the password for their bank account...they could have a real problem. It would be great for people if tools like 1Password were more prevalent, even built in to browsers. It becomes trivial both to create and maintain an unlimited number of secure passwords.