9 ms·
Remove my password from lists so hackers won't be able to hack me (2017)
- mikece 7y agoSwitch to KeePassXC on your Linux/Mac/Windows machine and an app that supports KDBX on your mobile device. For convenience, sync through iCloud or OwnCloud or whatever makes you happiest... and use KeePass's ability to create unique passwords on the fly for you, like this one: {"5vb"9d"Q}+;FKy/N:)Hn3A#.'mJ$amkuWq%_pX
- farisjarrah 7y agoLet me just say this: If you need to log into your google account on a weird touch screen device(looking at you, Honda's android auto implementation), do NOT have a super long random string password with a bunch of special characters in it. It will make your life hell whenever you have to type it. Its much easier to type in 8 words separated by dashes on a touch screen.
- Mathnerd314 7y agoIt's not hard to get KeepassXC to generate a medium-length alphanumeric password, which is IMO easier to tap-type than a passphrase, and it also has a passphrase generator.
- jankiehodgpodge 7y agoLike hell I'd type my Gmail password into some presumably highly insecure software like a car audio system.
- sp332 7y agoYeah, this would be weird. Doesn't Android Auto just use the account that's already logged in on your phone?
- vel0city 7y agoAndroid Auto is essentially just using your car's screen as a remote display. I don't believe any of the real processing actually happens on your car's head unit. Your data doesn't get shared with the head unit at all.
- yjftsjthsd-h 7y ago> Your data doesn't get shared with the head unit at all. As it should be.
- zentiggr 7y agoYeah, no, not doing that unless I get to security audit their code end-to-end. Have you seen the stories of auto APIs being completely unsecured, or just flat broken? No password, no.
- diminoten 7y agoYou are paranoid. Do you inspect every plane you board? Every car you ride in? Every room you sleep in?
- Avamander 7y agoThe planes or cars most people ride in don't ask those details to be fair.
- zentiggr 7y agoNo, but I have read stories of auto APIs that are as broken as "change the user ID at the end of the request string, and you can see the entire account details of any other registered user". That sort of incompetence makes me pause and think.
- diminoten 7y ago"I've read stories that people are able to take things out of cars if they're left unlocked." Okay, got it...
- zentiggr 7y agoFalse equivalency: When the manufacturer fails to secure PII, plus location history, plus control points of the car's internals, etc etc... that's far worse, more obscured, and much more in need of public disclosure than "door's unlocked, free contents!"
- diminoten 7y agoIt's neither far worse, nor more in need of public disclosure, at all, because it's the exact same, consequentially. Literally, even! In order to take advantage of your "exposed" PII, the adversary needs physical access to your car. Nothing false, it's actually equivalent.
- dessant 7y agoNeeding to link your car to your Google account already sounds like living in hell. ;)
- farisjarrah 7y agoI was actually trying to hack the head unit and it made my life easier by being able to log into google drive on the onboard browser and download some files.
- sk84life 7y agoYes..These Google devices scares shit out of me.. to be honest.
- bdcravens 7y agoyou can create “app specific” passwords for situations like this https://support.google.com/accounts/answer/185833?hl=en https://support.google.com/accounts/answer/185833?hl=en
- pm7 7y agoIt's designed for devices which cannot do Google's 2FA, not for normal use.
- alanfranz 7y agoIt's a joke. Not a 'real' PR.
- eranation 7y agoPrevious discussion: https://news.ycombinator.com/item?id=16009459 https://news.ycombinator.com/item?id=16009459 Also see: http://blog.assafnativ.com/2018/02/dolphins.html http://blog.assafnativ.com/2018/02/dolphins.html
- shkkmo 7y agoYes, the title should specify 2018
- pc86 7y agoThe page is from 2017.
- shkkmo 7y agoThe pull request was made at the very end of 2017 and much of the discussion happened in 2018 (as did the blog post by the originator of the pull request that is linked elsewhere in this thread.) I'm not really sure what the policy is when the linked content spans the new year.
- thedaemon 7y agoComments do not make the original post. We can have comments on some platforms for years after the OP. I think this way seems very logical, date the OP.
- TimTheTinker 7y agoThanks for posting this. I'm having a good laugh ... there's a lot of good humor in the comments on that issue.
- sdan 7y agoGot to change my HN password from "dolphin" now. Can't believe they figured it out!
- deleted 7y ago[deleted]
- jspash 7y agoI changed mine to dolphin2. Better safe than sorry.
- diminoten 7y agoLiar!
- deleted 7y ago[deleted]
- TwoHeadedBeast 7y agoEven better, d0lph1n
- philjohn 7y agoAll I see is * * * * * *
- em-bee 7y agosix stars? that's my password!!
- pseudosavant 7y agoSo long and thanks for all the fish.
- sysashi 7y agoThis was funny, liked the comments as well! (not sure if serious discussion is expected here, so I will leave my useless comment as is!)
- mundu_wa_hinya 7y agoReminds me of bash.org's hunter2 snip. http://bash.org/?244321= http://bash.org/?244321=
- jdoliner 7y agoIf you do a search in the repo you'll find that hunter2 remains a commonly used password.
- mundu_wa_hinya 7y agoOh wow! I'll have to start grepping for hunter2 everywhere....
- jcrawfordor 7y agoI regularly use hunter2 as the example or test value for passwords/keys. I wonder how many other people do this, and how many times it's accidentally leaked into production...
- Camillo 7y agoIt is a pretty good password. Just "hunter" is no good because it has no digits, so of course you'd add a "1"... but wait! It's actually a 2! That's the pro security twist the hackers won't expect.
- deleted 7y ago[deleted]
- Buttons840 7y agoIt will take twice as long to crack, because hackers will have to try all letter combinations ending in 1 first.
- slyall 7y agoI've got the devs using "password123" as the default in code because that value gets over-written. Freaks me out every time I see it and I'm trying to get them to use "overwritten_on_deploy" or something similar.
- jdoliner 7y agoI don't see my password on the list, but I want to make sure it stays that way. I wonder if they'd be willing to add a list of passwords never to be included on any list so as to keep their users safe.
- Hello71 7y agohttps://en.wikipedia.org/wiki/Russell%27s_paradox https://en.wikipedia.org/wiki/Russell%27s_paradox
- deleted 7y ago[deleted]
- gojomo 7y agoA pull-request is the wrong way to demand removal of personally-compromising information. If he instead routes his request to Github’s GDPR compliance department, it will be illegal for them to refuse the deletion.
- alanfranz 7y agoIt was a joke. Pure trolling from a security researcher.
- reificator 7y ago> A pull-request is the wrong way to demand removal of personally-compromising information. > If he instead routes his request to Github’s GDPR compliance department, it will be illegal for them to refuse the deletion. That's a good tip. If assafnativ ever wants to actually do that, I'm sure they will. Which will of course also remove it from all the password dumps it was initially included in, and protect assafnativ from all future hacking attempts.
- Shorel 7y agoEven if it was safely deleted from Github, there's the rest of the Internet to worry about. Definitely a great example of how the Streisand effect affects security.
- magnat 7y agoThere was this spoofed page that looked just like plain, unordered text file of passwords, that intercepted ctrl-f, displayed searchbox look-alike based on your user-agent and generated entries to match the password you are typing, so it looked as if your password was there. Anyone happens to remember the URL?
- Shorel 7y agoDamn this is pure evil.
- RcouF1uZ4gsC 7y ago> To add on to the translation of the idiom, that phrase literally means writing a sign that says "I did NOT bury 300 grand in this spot" Awesome idiomatic phrase!
- tialaramex 7y agoThis led me to look at https://mostsecure.pw/ https://mostsecure.pw/ To my surprise that password isn't listed by Pwned Passwords. That's much more secure than I'd expected and I commend its creators for their outstanding work.
- danShumway 7y agoI'm a little ashamed that it took me about 30 seconds of staring at this page before I refreshed it and actually got the joke. Good reminder to be careful using/trusting password generators online.