8 ms·
What do Sony and Yahoo have in common? Passwords
- deleted 14y ago[deleted]
- michaelt 14y agoIt's surprising to me that 60% of people don't appear to have changed their compromised passwords. Is there something wrong with how we tell people their passwords have been compromised - do you think we aren't making it clear enough what they need to do, or how important it is that they do it?
- Zirro 14y agoI suppose it's possible that many of these accounts were inactive, or people may have forgotten even signing up for the service. Or perhaps, despite all the reports in both tech and normal media, they just chose not to bother.
- MichaelApproved 14y agoWhat if there was a database of compromised email accounts and their passwords. Responsible websites could poll this database on a daily bases and reset the passwords of members who's accounts have been compromised on other websites. This way, if people use the same password on all websites, the responsible websites operators will protect their members accounts from being compromised. I know there are a ton of holes with this but maybe this initial idea could lead somewhere.
- 1880 14y agoWhen the Last.FM leak surfaced, I e-mailed all my non-technical friends who used it, warning them and explaining why and how they should change their passwords. Sadly, my message was received with a general tone of "you computer nerds, always complaining", and promptly ignored. People just don't care.
- crazygringo 14y agoYeah, it's the importance. And if 50,000 passwords are cracked, what are the odds that someone is going to use the cracked password to enter your account and do nefarious things, instead of the other 49,999 accounts? Pretty low. And with Yahoo Voice, what's the worst that's going to happen, really? If it's not the password to your bank account or Facebook, most people are going to figure, it's probably not going to affect me.
- CWuestefeld 14y agoI think his pie chart drives us to an incorrect conclusion here. It's not that people haven't changed their compromised passwords. The problem is actually that people choose inane passwords, like "password" and "123456". When people are doing that, you're bound to see significant overlap between the two sets.
- patdennis 14y agothe early evidence is that Yahoo! kept their passwords in the clear and certainly the dump appears to support this Wait, what? I'm no security expert, but how does that happen?
- sp332 14y agoI don't think so. The only evidence that the passwords were stored in the clear is that some "strong" passwords were broken. But if you look at the LinkedIn dump (which was hashed) there are plenty of strong passwords that were broken.
- sk5t 14y agoThe author, Troy Hunt, keeps extensive lists of actual passwords (millions upon millions gathered mostly from other disclosures). Many "strong looking" passwords turn up in these lists... all sorts of keyboard patterns, numbers tacked onto permuted words in various languages, etc. Of course it's difficult to verify the genuineness of most disclosures like this, unless the victim company decides to fess up.
- Zenst 14y agoThis could of been from a hack done years ago, milked for all entirity in secret and then released years later. Alot of passwords would still be the same, people habitualy if not controlled to change there passwords every N days will not bother unless some event dictates thay should and then if they can avoid it then alot will sadly. Sadly the human finger fits perfectly into the human ear and this is how alot of people handle alot of problems. Now that all said if you look at any password system you will find common passwords and if you allow your user to use things like football teams, there own username and words like "god" "jesus" etc then you will get a standard statistical spread. The only conclusion you can make is if you get a million needles and chuck them in the air and do it twice that in pile A and pile B you will find some that point north, its the way it goes. So what does sony and yahoo have in common - passwords picked by humans, used by humans - just like alot of password systems, be they hashed, tripple hashed or plain old text.
- omni 14y agoThis guy only used 302 from a dump of 453,491 passwords to come to these conclusions. I can imagine no reason why he'd intentionally invalidate his analysis by using such a low sample size unless this conclusion doesn't actually hold when you use a significant sample. I am highly skeptical.
- biot 14y agoI read it differently: "This is from a sample size of 302 common accounts and unsurprisingly, the strength of those passwords leaves a lot to be desired:" The word "this" refers to the passwords list after the colon, not the preceding analysis. It really should have been written as "The following list of weak passwords is from a sample size of 302...".
- troyhunt 14y agoThe emphasis should have been on "common" - there were only 302 emails out of the full sample which appeared in both breaches. I would have like a larger sample size, but that's all there was.
- omni 14y agoAh, my mistake. Thanks for clarifying!
- unreal37 14y agoI think this article jumps the gun a little. There's no evidence that this is indeed from Yahoo Voice, no evidence how old it is, no evidence how Yahoo stored their passwords... And he's only found 300 accounts that existed in both Sony Systems and Yahoo. Quite a leap from some random file someone posted to the web to this.
- troyhunt 14y agoYahoo! have confirmed the breach: http://news.cnet.com/8301-1009_3-57471178-83/yahoos-password-leak-what-you-need-to-know-faq/ http://news.cnet.com/8301-1009_3-57471178-83/yahoos-password...
- jackalope 14y agoI think focusing on password length as an attribute of strength reveals an intrinsic weakness of passwords in general. We're reaching a point where any password that is humanly memorable is not in the set of strong passwords. It's a tragic flaw that all permutations available from an entropy pool aren't equally strong. The fundamental problem of identity assurance needs to solved, and it's sad that passwords represent both the state of the art and its weakest link.
- CWuestefeld 14y agoLess than 1% of passwords contained a non-alphanumeric character, only 4% actually used more than two character types I think we're past the paradigm of gobbledy-gook passwords now. As we learned from xkcd [1], it's possible -- in fact, easier -- to construct a secure password that's also readable as needed. [1] http://xkcd.com/936/ http://xkcd.com/936/
- jackalope 14y agoThat comic is misleading. Depending on the method of attack, the suggested password can be easier to crack. Attackers aren't constricted by the number of characters, but by the number of tokens. Are you sure that one of those passwords comes from a higher number of permutations?
- CWuestefeld 14y agoYes. If you choose your four words from a dictionary of, say, 2000, then there are 1.6e13 combinations -- about 44 bits of entropy.
- jackalope 14y agoIf you choose 11 characters from a conservative set of 72, then there are 5.2e19 combinations. Isn't that stronger?
- troyhunt 14y agoThe comic is amusing, but it only works if you can apply it uniquely across accounts. Once you start creating unique passwords of that length you can't remember them. Get a password manager and forget about patterns - the XKCD approach doesn't work without serious compromise.
- deleted 14y ago[deleted]