6 ms·
Anonymous posts usernames and passwords of US Congress staffers
- thezilch 13y agoThey've got nothing to hide, right? Is this FEMA? If our government can't be arsed to secure their authentication servers and passcodes (eg. salt+hash+fuckitandusebcrypt), how the hell can they be trusted with other's private data?
- res0nat0r 13y agoCongressmen on the hill are not the same people that the NSA is employing to do technical surveillance work and data collection analysis.
- thezilch 13y agoSure they are, the NSA precisely characterized Snowden as a high-school dropout. As well, I'm not convinced Congress staffers shouldn't be just a schooled as those data analysts. These are the folks first in line to help educate our Congress! They help or wholesale write bills! You're probably right though; no freaking wonder this circus has allowed the NSA and the like fly under their nose.
- gmuslera 13y agoconsidering how much of those passwords are "password", i'd say that they don't feel like having anything to hide.
- showerst 13y agoThese look like they came from some sort of third party CRM, possibly http://www.iconstituent.com/ http://www.iconstituent.com/ given the number of variations of iconstituent in the password list. It says something about how thoroughly they vet their vendors, but it's not 'our government's security. (although requiring a full audit that deep before letting them pay a third party just makes them more lumbering and tech-phobic...)
- jstalin 13y agoSome of my favorite passwords from the list: notalentassclown3 password2 Password12 password5% password Password14 Password1 PASSWORD Password1@ password3# Password!1 Password45 etc...
- seferphier 13y agothis is my favorite Eric.Slocum@mail.house.gov: Fuckface^1
- rollo_tommasi 13y agoI'd vote for whoever employs the guy whose password is 'Elimgarak06!'
- codereflection 13y agoI like the all uppercase PASSWORD, like the intensity makes it more secure.
- foobarbazqux 13y agoYes, only a single capital letter is needed to make it more secure against automatic methods. But all-caps is probably more secure against an in-person attack, way more so than just 'password'.
- pvnick 13y agoWow. Bad move, Anon (and I'm the last person who would normally say that). This was a really crappy thing to do to innocent folks just trying to make an honest career, many of whom probably use the same credentials for their online banking and other important services. It gives a bad name to "hacktivists" (which are growing increasingly important in holding our government accountable) and will only take credibility away from the cause of transparency. Congress members will very likely take an "us vs them" mentality and lump Anon with "them" who want transparency wrt the NSA revelations. Counter-productive and juvenile, that's all this was.
- ddq 13y agoPolitics. Honest career. Pick one.
- rbanffy 13y agoIf you are honest and don't want to enter politics, you cannot complain when less honest folks do so.
- VladRussian2 13y agoIf you are honest and don't want to rob other people, you cannot complain when less honest folks do so.
- 6d0debc071 13y agoThat's actually a pretty good argument if there were a more or less constant number of robbers. In a situation where you were definitely going to be robbed - as seems to be the case if you want it to be analogous with government: Would you rather be robbed by a complete drugged out psychopath who'll kill you if you twitch or someone relatively calm who definitely won't kill you if you just hand over the money?
- VladRussian2 13y ago
- Afforess 13y agoFavorite password: cody.stewart@mail.house.gov: iConstituent Obviously this leak is bad, but I think it's also humanizing. Staffers are people.
- 542458 13y agoCuriously, more three people have the password Iconst!tu3nt, and one more that looks like a garbled version thereof. I wonder why five different people are using near-identical passwords - a default of some sort? Iconst!tu3nt x3 iConstit*09 iConstituent I feel bad for the people whose passwords were leaked, but I'm happy to see that there's (as far as I've seen so far) terribly embarrassing among the passwords. (Edit: okay, I was wrong on this one. notalentassclown3, Fuckface^1, poopypants1, DallasSucks10! and 1044shit, I'm looking at you) Also funny: Senatebound2012!
- superchink 13y agoLooks like iConstituent is a CRM that they probably all use.
- atlbeer 13y agoYep http://www.iconstituent.com/constituent-gateway-crm/ http://www.iconstituent.com/constituent-gateway-crm/
- wtvanhest 13y agonotalentassclown3 Its from office space right?
- fnordfnordfnord 13y ago>NOTE: FOR THE PURPOSES OF BEING FAR TOO GENEROUS WITH YOU GUYS, WE HAVE REMOVED SOME OF THE PASSWORDS AND SHUFFLED THE ORDER OF THE REMAINING ONES. THESE ARE ALL CURRENT, VALID CREDENTIALS BUT THEY ARE NOT IN THE ORIGINAL PAIRINGS. WE RESERVE THE RIGHT TO SPONTANEOUSLY DECIDE THIS RESTRAINT WAS UNJUSTIFIED. Some are pretty easy to guess who they belong to. like TX32republican!
- djKianoosh 13y agoSome people use personally identifiable info in their passwords. Even though they shuffled passwords around so they don't match the username, if the user's name or address is in the password... yikes
- antimora 13y agoI am very surprised the policy of password strength is very weak. Allowing "smith" as a password? It's too weak that makes me suspicious about the origins of these passwords.
- jaynos 13y agoMost (probably all) of the Federal government requires password changes every month or so (not completely sure of the timeline) and you can't use previous passwords. This leads to shitty passwords just so people can remember something that always changes.
- Aldo_MX 13y agoOfftopic: One bank I use enforces 8 characters max and changes every 3 months, I ended up with /.+[0-9]{2}/ as the password since I would never trust my bank credentials to any means to save the password, and I would never write it in anything that it's not a password input (that includes a piece of paper). If my bank get's hacked, don't be too harsh with my password, I swear I can't remember a new, unique, secure and constrained password every 3 months :(
- showerst 13y agoThese look like they came from some sort of third party CRM, possibly http://www.iconstituent.com/ http://www.iconstituent.com/ given the number of variations of iconstituent in the password list. I'd be willing to bet that the actual house/senate domains require strong passwords, I've interacted with their IT in a few situations and found them to be on the ball.
- nothingToHide 13y agoCrap. I didn't think the link would actually take me to the actual list of emails and passwords. Now I'm probably in the NSA's list. Well, thank god I HAVE NOTHING TO HIDE. (I think...)
- bound008 13y agoOh the classic and secure "Password1". Mixed case and even alphanumeric.
- cloverich 13y agoWhat is the point of doing this?
- p37307 13y agoGrief, the passwords are so lame. Do these people not realize how important strong passwords are. Corker06. lol. Senate09.
- tjbiddle 13y agoSearched for "password" - 36 results. The majority some iteration of 'password1', 'Password1', 'password2', etc. Really wish government employees would be forced to use more secure passwords, or at the least heavily trained on the importance of them.
- fnordfnordfnord 13y agoAssuming this is real. Most of these look like default passwords chosen by a clueless office administrator. They're all so similar.
- XEKEP 13y agoSo what do we have? A bunch of weak passwords. Not bad they are revealed, actually, should educate some a bit. Still, revealing the passwords without the email addresses would've been a bit more responsible. On the other hand, do they really store house.gov passwords unencrypted? I'm not even talking about salted vs unsalted hash here, just plaintext? Seriously?
- showerst 13y agoThese look like they came from some sort of third party CRM, possibly http://www.iconstituent.com/ http://www.iconstituent.com/ given the number of variations of iconstituent in the password list.
- radmuzom 13y agoInteresting. While I do not support this, there are still users who have their password set to 'Password1'?
- codereflection 13y agoSome of these are really easy to match up. Using part of your name as your password is epically stupid.
- jlgaddis 13y agoI'm laughing now but I probably won't be later. I'm afraid that the government will use this incident as "proof" that what they're doing thus far isn't "enough" and they need even more power and control... and, given the victims of this attack, I'm certain they'll get it.
- kunai 13y agoThe first thing that came to my mind was: god, these are horrible passwords.
- h0w412d 13y agoWell, have you ever not thought that after a password leak?
- lukifer 13y agoMakes me wonder if the responsible thing to do when running a web service is to constantly dictionary-attack and brute-force your own server, and whenever it gets a hit, email the user and force a password change. In theory, the userbase would evolve towards better passwords over time.
- lukejduncan 13y agoCan we get a warning in the title that this doesn't just link to an article?
- peterwwillis 13y agoWhatever happened to plain old defacing a website, like back in the day? This "dox" obsession isn't nearly as cool as proposing marriage to Madonna from a corporate website (though these days I guess it would be miley cyrus?)
- TheCowboy 13y agoI wonder how old this data is. I looked up one person I know who hasn't worked on the hill since 2010.