12 ms·
Gawker Website source, databases & passwords now on BitTorrent
- watty 16y agoThis is a huge breach yet users have to scroll down a full page on Gizmodo.com to find a small article about it.
- joeybaker 16y agoWorse, the Gawker post on the issue http://gawker.com/5712615/commenting-accounts-compromised-++-change-your-passwords http://gawker.com/5712615/commenting-accounts-compromised-++... releases no details. Instead of giving a detailed description of what happened, they simply say, "change your password." With that level of detail, you might think they're now afraid to even write "4Chan."
- puredemo 16y agoAnd the post doesn't allow comments either, so there is no way for users to mention the extent of the compromise.
- Jem 16y agoThere's a red bar across the top of the site linking to their article - is this new?
- deleted 16y ago[deleted]
- nicksergeant 16y agoOpenID as a solution, not so much. It's a roundabout solution to a bigger problem. A solid password distribution and management strategy is far more effective. 1Password for Mac handles that pretty well for me.
- deleted 16y ago[deleted]
- dholowiski 16y agoAt this point, I wouldn't trust an email from gawker with a password reset link, considering they've just been hacked. Sadly I think most users would.
- jalada 16y agoFor the record they don't send reset links, they send you a new generated password for you to log in and change.
- ShabbyDoo 16y agoSo, were these "passwords" stored as salted hashes?
- estel 16y agoI've been trying to find this out also. There's no indication that they are; but the only indication that they aren't was them saying that shorter passwords will be much less secure.
- andrewjshults 16y agoIgnore this and see tptacek's post about bcrypt instead. This is why my preferred hashing scheme is username + seed + password, so that even if user1 and user2 both use "password" as their password, they'll end up with different hashes. That way if the database is compromised you can't do frequency analysis against the hashes to make guessing common passwords easier.
- tptacek 16y agohttp://codahale.com/how-to-safely-store-a-password/ http://codahale.com/how-to-safely-store-a-password/
- andrewjshults 16y agoRegarding bcrypt - does it still make sense to do seeding on those since the key wouldn't be changing? I've also seen wrapping sha1/etc and looping it like 1000+ times to introduce a time factor in, but that doesn't seem like the best solution.
- kmfrk 16y agoHaving seen the pastebin link, these guys use really, really poor password. Only alphanumeric - usually just one of the two - rarely with capitalization, and nothing else.
- pyre 16y agoI was under the impression that the ones that were displayed w/ password were just the ones where the password was reversed from the hash. Does that apply to all accounts, or just to ones with weak passwords (i.e. there may be selection bias in that list).
- redthrowaway 16y agoThe group responsible put up a pastebin here: http://pastebin.com/9rRmf6W5 http://pastebin.com/9rRmf6W5 (Warning: questionable legality) It lists a bunch of the password/email combinations (plaintext), and tells a bit about how they did it. I'm guessing they used a dictionary attack for the easy ones. Also displays chat logs from campfire that show the staff in a highly unfavourable light. Then again, their work does that just fine without any outside help.
- alanh 16y agoThe parent comment is likely referring to admin & username passwords for people working at Gawker Media, such as Gizmodo, Lifehacker, and Kotaku contributors. All the usernames and passwords for users with {@lifehacker.com, @gawker.com, etc.} email addresses in the torrent (plaintext, not hashed). The torrent claims Nick Denton’s password was an 8-character sequence of even numbers, and that he used it everywhere. (Edit in reply: The hackers used this on e.g. his Twitter account IIRC so it wasn’t truncated to 8 characters.) Some of them are even '11223344' or a substring of the author’s username!
- wahnfrieden 16y agoThis isn't entirely accurate. Their hashing mechanism only hashes and stores the first 8 characters of the password. So you only need to get the first 8 right, even if the password is 12 long. That also means that, although unlikely for some, '11223344' could have actually been '11223344aBc$!q'. Not that it would have mattered though!
- arn 16y agoany chance it's related to this? https://forum.bytemark.co.uk/comments.php?DiscussionID=2701 https://forum.bytemark.co.uk/comments.php?DiscussionID=2701
- joeybaker 16y agoNo. Gawker uses Google Apps for email. https://www.google.com/a/gawker.com https://www.google.com/a/gawker.com
- citricsquid 16y agoThe stealing of data is from ~November, not today. It just happens they "released" it today.
- wizardishungry 16y agoDoes anyone have any information on changing all their account passwords at once? I don't use the same password for any sites, but unimportant sites like blogs, etc. I use fairly similar passwords on.
- wippler 16y agoFor anyone who is interested in more details, check out the readme file for how it actually went, atleast a rough sketch of it.. http://pastebin.com/cpb7ndV8 http://pastebin.com/cpb7ndV8
- sero 16y agoSounds like they probably used social engineering to get initial password(s) and thanks to poor security practices used those to go from there? Not to sound malicious or impersonal, but breaking something so wide open is like a solving a hard puzzle, I'd be really interested to hear more details on how they actually did it.
- drivebyacct2 16y agoI can't stand Gawker and Gizmodo and the shit attitudes of the people there. Love to see their attitude in Basecamp and see them get owned hard. I know it's juvenile, but I'm just being honest. Now I'm going to go check and make sure I didn't have an account with them, ever.
- alanh 16y agoI think I am going to be checking the dump to ensure my password is not among it… Remember, don’t use the same password across the Internet. Here’s why. Edit: It’s there, apparently as a DES hash. … Update 2: The first two characters are the hash. So if you use a tool like https://hash.online-convert.com/des-generator https://hash.online-convert.com/des-generator you are going to put your password in the “Text you want to convert…” box and the first two characters of your hashed password in as the “Salt (optional)”. Then you will see the “Calculated DES Hash” which will be the same as the hashed password from the torrent if you knew or guessed the password correctly. E.g. Your Lifehacker password is “hackern”, but in the torrent, it’s just “8h48GPxmwy.EA”. Just to show the torrent is legit, you go to the website I entered above, enter “hackern” and “8h” as the salt; it will spit back “8h48GPxmwy.EA”. Update 3: “OFFER HN”: The most paltry “Offer HN” ever — send me your username or email address and I’ll grep both files for you to see if your password and/or hash is in one of them. My email is contact-at-<HN username>ogan.com
- cheald 16y agoI already did this. I'm tempted to set up a utility page where you enter your email and the utility just tells you if it was in the DB, but I don't know how legal that would be. Checking the data for personal defensive purposes is arguably defensible - setting up a tool based on that data (even benign) is likely less so.
- iregdtoreply 16y agoPlease do. I don't want to download the torrent and I don't know if I have ever commented on Gawker but there is a slim chance I might have.
- ra 16y agoWhat about emailing everyone in the DB?
- cheald 16y ago"Unsolicited scary email from some guy that got my email from a hacker" sounds like it would only be slightly less legally dangerous than just straight up forcing hashes and posting them.
- jdbeast00 16y agodoes anyone know if their other sites db's were compromised aside from gawker.com?
- cilantro 16y agoIt seems to me that all their sites are run off one complicated db schema. I just confirmed that my Lifehacker user name is in there.
- kacy 16y agoThis is serious. I just checked out the torrent with the text file of the 200,000 cracked passwords. I searched for @me.com account and logged into someone's apple account. It was possible for me to order stuff via their account. I quickly emailed the guy to let him know to change his password. Gawker needs to take responsibility of this situation and email everyone in their database.
- CoachRufus87 16y agoIf they haven't done so already, then they've lost any and all credibility as a company in my eyes.
- wildmXranat 16y agoYou mean it hasn't happened already? Gawker scrapes the bottom of the Internet barrel.
- JimmyRuska 16y agoThis is what happened with monster.com and a lot of other big sites that got hacked. I bet most don't even make it public, much less email their members. They work so hard on brand reputation and image, then it all goes down the drain because some admin used a weak pass. It's not so easy for them to throw away their christmas bonus and job security. They'll do the minimal.
- ibejoeb 16y agoGawker posted password change guidance on its website, but no mention is made of having attempted to directly contact those affected, so I'll assume they didn't. I don't know who's handling this for them. We have the list. Anyone with a MailChimp account want to be a good samaritan? Edit: I'll certainly help, but I and my girlfriend, Stella Artois, have been lamenting the embarrassing loss our Jets suffered this evening, so I figured I'd float the idea for vetting first :) Edit 2: Wow: I know a lot of people on this list. I'm letting them know, and recommend that others scan on behalf of friends and family as well. I've been told that there has not been active communication; wish gawker would confirm either way.
- anigbrowl 16y agoThe passwords aren't very important, although I can see why that'd be an issue. But those internal chat logs are going to be a bit of a problem. For Nick Denton, that is.
- olalonde 16y agoAnyone how they got access to their Campfire account? (That's where they found the server passwords)
- cheald 16y agoIf I had to bet? Firesheep or similar + a writer sitting at a Starbucks. Your guess is as good as mine, though. Campfire's under SSL, but people re-use passwords and it's trivial to lift a password-in-the-clear off of a public wireless hotspot. If you wanted to target Gawker, it wouldn't be hard to identify people practicing poor security and just watch them until they slipped up.
- redthrowaway 16y agoThis is what mailinator and, failing that, tenminutemail accounts are for. Why people sign up for random sites with their personal emails just to comment on articles is beyond me.
- deleted 16y ago[deleted]
- lotides 16y agoCan Gawker be held legally liable for maintaining poor security standards and incompetence leading to this? Can anybody cite related laws or cases?
- MiguelHudnandez 16y agoCalifornia's SB 1386 does not seem to apply, as there is no "Personal Information" in the leaked database. One thing open to interpretation would be whether the password in the file could be used to access someone's bank account. If someone uses the same e-mail address and password at both sites, that would be true. Section 1798.29, E, 3 -- Definition of Personal Information Account number, credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual's financial account. * http://info.sen.ca.gov/pub/01-02/bill/sen/sb_1351-1400/sb_1386_bill_20020926_chaptered.html http://info.sen.ca.gov/pub/01-02/bill/sen/sb_1351-1400/sb_13... I am not a lawyer.
- jtagen 16y agoI wonder if there's an option for an ISP to proactively secure these accounts. GMail has phone verification for backup, they could temporarily disable the account of anyone who has a matching password. Odd, I'm sure I had a lifehacker comments account, but my username isn't listed. No complaints though.
- Q6T46nT668w6i3m 16y agoHas anyone checked if source/ contains the source for their proprietary CMS? From Felix Salmon: Most of the value of Gawker Media lies in Hungary—but how much value is there, really? To a large degree that depends on what Denton decides to do with his proprietary technology. Other blogging platforms are worth nine-figure sums—Tumblr just got a valuation of $135 million, while Automattic, the parent of WordPress, turned down a $200 million acquisition offer three years ago, when it was much smaller than it is today, and subsequently raised money at a valuation north of $150 million. I know a lot of people at big media companies who struggle with the limitations of WordPress, and who would pay good money to license an alternative web publishing technology, if it was robust and proven. Big companies are already licensing the NYT’s Press Engine mobile-publishing technology, and it’s rumored that at one point Denton was talking to Bonnie Fuller about licensing his technology to her nascent website, although that never happened. http://news.ycombinator.com/item?id=1998642 http://news.ycombinator.com/item?id=1998642
- quizbiz 16y agoI was under the impression that Gawker Media is indeed powered by Wordpress. source: http://wordpress.org/showcase/tag/gawker/ http://wordpress.org/showcase/tag/gawker/
- jedsmith 16y ago> Has anyone checked if source/ contains the source for their proprietary CMS? Yes, it does. Several copies of it, including trunk.
- uxp 16y agoThe archive of trunk appears to be one with shared assets, not the development trunk of the CMS. I could be wrong however, but I see no similarities between the layout of "trunk" and the other archives that were clearly live web-facing assets.
- mikeklaas 16y agoThose valuations have nothing to do with "CMS technology"; it is instead the userbase, ecosystem, and mindshare those platforms have acquired.
- paulitex 16y agoI've download the torrent, convenient of them to give an email address with each cracked account. I'm currently writing a little script that parses all the address and emails the owner a heads up. I gotta step out so I won't have it done for 2-3 hours and I thought I'd post here in case anyone else has that idea (don't want to flood the victims).
- fendrak 16y agoFor a little background information on DES password hashing, check out this assignment from my Computer Security class at UT Austin: http://www.cs.utexas.edu/users/byoung/cs361/crack-assignment.html http://www.cs.utexas.edu/users/byoung/cs361/crack-assignment... It gives a little bit of background information on password hashing and salting, and on simple password cracking techniques.
- dataminer 16y agoIts a good idea to use Keepass and Keyfox to generate different secure passwords for every site instead of using one weak password for all the sites.
- drivebyacct2 16y agoWeird... One of my throwaway accounts appears with a name I know I've never used before. Then again, I had someone sign up for a Facebook account with that email address once too...
- drivebyacct2 16y agoWTH? Why downvote this? Especially as I've seen users on Gawker's sites, HN and reddit mention the same issue. Really? What is the purpose of downvoting this?
- nhangen 16y agoI'm in there, and I'm grateful to the HN community for showing me how to find out. This is rather alarming...I've passed it on to my newsletter subscribers, Twitter, Facebook, etc. Kind of ironic really, considering the whole secrecy vs non-secrecy debate.
- deleted 16y ago[deleted]
- philfreo 16y agoSeriously, use 1Password... it's great.
- Du4No 16y agoKeePass as a free alternative
- wnoise 16y agoAnd the clone keepassx for running on unixes.
- jacquesm 16y agoUntil they get hacked...
- there 16y agothey don't store any passwords.
- jacquesm 16y agoThat doesn't mean they can't be compromised. After all, if 1 password gets hacked the passwords that are generated could be sent to two parties instead of just to you.
- ubernostrum 16y agoAfter all, if 1 password gets hacked the passwords that are generated could be sent to two parties instead of just to you. And if someone mounts a camera in the smoke detector in my apartment they could see me type in the double super secret password whose plaintext has never been stored by a computer. So what's your point, exactly? Tools which generate good passwords and store them locally on your computer with decent-enough security are light-years ahead of what most people do, and their use should be encouraged.
- bhrgunatha 16y agoDoes anyone have a list of sites that gawker owns - I have no idea which sites I need to potentially check. EDIT: Nevermind - it seems that resetting your password at gawker.com resets for all of their sites.
- norova 16y agoI'm currently sending emails to the first 50,000 addresses listed in the database dump via SendGrid. I only have 50,000 credits left for this month, but at least that many will get notified.
- petercooper 16y agoA bit too late now, but that violates at least the first three terms of the SendGrid e-mail TOS and I wouldn't be surprised if SendGrid got a "bit upset" about it..
- norova 16y agoWell, haven't actually clicked the send button yet.. was waiting for the import to finish. I'm second-guessing the foolhardy good samaritan effort now, though. ;) It's a free account that I got via an AppSumo bundle, so no real loss to me if it gets terminated, but I'd rather not go that route to begin with, ya know?
- iphoneedbot 16y agoIm curious, how come it only shows 65k email addresses, but everywhere Ive read reports email addresses totaling over a million
- fhars 16y agoMy guess: It only shows so few accounts because you are opening the file with a spreadsheet program that is limited to 65536 rows.
- iphoneedbot 16y agoAh! Gotcha! hat tip
- jbm 16y agoLooks like it is quite easy to shut off ads on Gawker. They do a simple boolean check to see if you have a "noad" cookie set. Try entering this into the console. javascript:document.cookie='noad=true; expires=Thu, 2 Aug 2021 20:47:11 UTC; path=/'; This shuts everything off, except for one ad at the top. (Put a bookmarklet for this if anyone who wants to try it out: http://bit.ly/exvive http://bit.ly/exvive)
- flexd 16y agoI had no clue what gawker was until i saw this. Am i expected to
- flexd 16y agoSeems half my comment disappeared. (magic?) So did everyone know about this site or am i just slow? Half of my comment actually disappeared when i posted this as well. Had to edit it to get everything in.
- danilocampos 16y agoMy credentials were in the pile. So, uh, how come I and everyone else affected don't have an email in our inboxes from Gawker right now, marked as urgent, explaining the situation? Doesn't that seem like the right thing to do?
- Q6T46nT668w6i3m 16y agoMax from Gawker claimed that users were notified yesterday afternoon: http://www.ilxor.com/ILX/ThreadSelectedControllerServlet?showall=true&bookmarkedmessageid=2181143&boardid=40&threadid=45134 http://www.ilxor.com/ILX/ThreadSelectedControllerServlet?sho... FWIW: I wasn't notified.
- tallanvor 16y agoI wasn't notified either. At least not by Gawker. Apparently the people at hint.io took the initiative to send out emails, which is nice of them, but hopefully they don't use the email addresses for anything else.
- tenaciousJk 16y agoI think they had a competition to see how many buzzwords they could fit in to a single, run-on sentence: http://hint.io/about http://hint.io/about
- dwynings 16y agoThe email addresses have already been deleted from our database.
- dacort 16y agoLooks like somebody decided to spam the heck out of Twitter with those compromised passwords. http://twitter.com/#!/delbius/statuses/14235293116792833 http://twitter.com/#!/delbius/statuses/14235293116792833
- bigiain 16y agoI just saw a bunch of spam status updates on my sisters Facebook account that'd just be way too much of a coincidence to not be related to this...
- bigiain 16y agoI just saw a bunch of spam status updates on my sisters Facebook account that'd just be way too much of a coincidence to not be related to this...
- sams99 16y agoWhen will people learn to use bcrypt for their passwords, and on that topic, when will a "security expert" bless it http://stackoverflow.com/q/3722780/17174 http://stackoverflow.com/q/3722780/17174
- liedra 16y agoI have an io9 account (that's a Gawker site) but my email isn't showing up in a grep of the db dumps. Perhaps this is not the entire database after all? (I didn't use Facebook Connect.) I must admit I'm a bit intrigued as to why mine's not there. Anyone else in this boat?
- lzm 16y agoFrom the readme: After gaining access to gawkers MySQL database we stumble upon a huge table containing ~1,500,000 users. After a few days of dumping we decided that 1.3 million was enough.
- liedra 16y agoThanks, I must have missed that! I also saw an additional claim on the "Gnosis explains" article: "The actual database size is 1,247,897 rows, which is 80+% of their database." - http://www.mediaite.com/online/exclusive-gawker-hacker-gnosis-explains-method-and-reasoning-behind-his-actions/ http://www.mediaite.com/online/exclusive-gawker-hacker-gnosi... I wish I could win a raffle with that sort of luck though! ;)
- ericflo 16y agoWas this a Campfire hack, or did they happen to know a username/password combo and try Campfire first?
- enko 16y agoDamn, I'm on the list as well. This is the straw that broke the camel's back - I'm buying 1passwd, and converting to it wholesale.
- beaumartinez 16y agoTPB have removed the torrent.
- Keyframe 16y agoEarly Christmas for spammers. What a disaster.
- trucious 16y agotorrent not found..
- quellhorst 16y agoThe torrent has been removed. Is there another place to download?
- soult 16y agoAs for all files that have recently been removed from thepiratebay, they are still reachable with this url (where ID obviously is the numeric ID seen in the original torrent URL): http://torrents.thepiratebay.org/<id>/somerandomnamefortorrentfile.torrent http://torrents.thepiratebay.org/<id>/somerandomname...
- brandnewlow 16y agoRandom datapoint: My e-mail was one that got hit in this hack. 15 minutes ago my Twitter and Gmail both just locked me out. I was able to set new passwords via mobile verification, but that was pretty spooky and clearly someone is going after the people who got exposed here.
- brandoncor 16y agoSo you used the same password for Twitter, Gmail and Gawker? Or did the accounts get compromised some other way?
- brandnewlow 16y agoYup! I make no excuses. That's been remedied now.
- MrFoof 16y agoEven if you're not, my email address is getting spammed with password reset attempts for Battle.net, LinkedIn, Facebook, Amazon, one of my banks, Twitter, etc. Granted, all had different passwords, but people are taking full advantage of this information being made public. Personally I'm not as worried about Gnosis or 4channers doing anything particularly malicious with the data -- that's not their goal. Their goal is to publish it so other people do malicious things with the data, with all the resulting animosity being directed to Gawker.