9 ms·
Weak passwords brute forced
- voltagex_ 13y agoGood reminder to add 2FA via https://github.com/settings/two_factor_authentication/configure https://github.com/settings/two_factor_authentication/config...
- voltagex_ 13y agoIf you use GitHub via SourceTree, this may not work though... Solution: https://confluence.atlassian.com/display/SOURCETREEKB/Two-Factor+Authentication+%282FA%29+with+GitHub+in+SourceTree https://confluence.atlassian.com/display/SOURCETREEKB/Two-Fa...
- allochthon 13y agoI think two-factor auth should be the new basic auth. Every site should provide it, either directly or through an integration with a trusted OAuth provider. I'm waiting for the day that the security people work out a solid federated single-sign-on system that gains widespread adoption.
- Goopplesoft 13y agoShameless plug: to get alot of sites using 2FA in a standardized manor is exactly why I made GAuthify (https://www.gauthify.com https://www.gauthify.com)
- forrestthewoods 13y agoHow is this possible? I would expect repeated failed login attempts would force a timer making a brute force attack impossible? Or at least more difficult. Is that not the case or am I missing a key piece of info? (Serious question, not trying to troll or be smug.)
- ajtaylor 13y agoThe article did mention the use of 40k unique IP addresses, so I'm guessing their rate limiting is based on IP address and not the username or IP+username combination.
- X-Istence 13y agoWhy not both?
- fragsworth 13y agoMaybe they're doing this now that it's a real problem? At any rate, don't store really sensitive stuff on Github. It's a bad idea for many reasons, security flaws being one. In particular, keep in mind things like AWS server credentials which might go in your repository.
- rythie 13y agoDoing it by username means the real user can lose access to their account, whilst it is being attacked, even though they might have strong password.
- pavs 13y agoFrom the blog post: "While we aggressively rate-limit login attempts and passwords are stored properly, this incident has involved the use of nearly 40K unique IP addresses. These addresses were used to slowly brute force weak passwords or passwords used on multiple sites. We are working on additional rate-limiting measures to address this. "
- Pxtl 13y agoI've seen this mentioned before - using a tremendous number of IP addresses across a tremendous number of sites and over a massive length of time to perform a very low-grade incessant brute-force attack. It means that any weak password anywhere is always vulnerable because everybody is always under low-grade brute force attack.
- Wingman4l7 13y agoWhat was the purpose? Were the repositories private? Was the attack targeted toward known accounts working on new projects -- i.e., industrial espionage?
- Fargren 13y agoIf you get a user-password combo, you can try it in more sensitive sites that may have stronger protection against brute force attacks. People reuse passwords a lot, specially the kind of users that use weak passwords on the first place. If the account has an email address connected to it, you can also try the password against the e-mail account. That can be worth quite a lot if it works.
- Wingman4l7 13y agoAh yes, what with the usual "email address being the skeleton key to your online identity" and all. I keep forgetting about this, and find myself wondering why the heck people are phishing me for my LinkedIn account login.
- rurounijones 13y agoI just checked my security section (Didn't know about that!) and there were 12 attempts on my private, totally non-corporate, account. My password has not been reset by github but I have updated it anyway. On a sidenote I think that is a very clear and well written overview with clear details and a nice reminder about a section of the site that I was not familiar with.
- Wingman4l7 13y agoI just checked too (https://github.com/settings/security https://github.com/settings/security) and I had 6 attempts, all from unique IPs. Asked a friend of mine and he had 6 attempts (all from unique IPs) as well.
- patio11 13y agoI'm going to guess it was simple spray-and-pray. (My account took its fair share of compromise attempts, too, probably because I use the same username everywhere so it's going to be in many modern dev-heavy password dumps.) Github is, for better or worse, a high-value target these days. Compromise of a Github account will often get you credentials which you can use to compromise high-value targets, for example production machines. (Example from the Rails world: if someone gets read access to your git repository, expect them to figure out your secret token which you use for HMACing sessions to prevent forgery. If an attacker can forge sessions, they have remote code execution on your production servers. You can assume they will go directly from code execution to root on those servers, and from root on those servers to a systemic compromise of your entire network (if they want to do that).) Use your imagination on what a mass compromise of accounts gets you. The simplest possible example is grepping for /bitcoin/, finding the full source code and credentials for a Bitcoin exchange, and rooting them then emptying the hot wallet. That results in fairly obvious economic advantage, right? You could also use scriptable attacks to root thousands of big-n-beefy production machines on fairly trusted IP addresses, then add them to a botnet, which you'd use for spamming or various other nefarious activities. Then, even farther down the list, you have a dedicated adversary actually go through every repository they got access to and look for something uniquely fun to do with that particular target. If you were looking to do industrial espionage on a particular target, you'd probably pick a way that was less likely to be detected and cause a company-level security response. (Use passive recon to identify one or a few likely target email addresses, find one or a few likely passwords for them, and try them first. Heads you win, tails you just left evidence in a log of perfectly normal user behavior. You might follow up this perfectly normal user behavior with a social engineering attack.)
- Wingman4l7 13y agoWow, ~40,000 unique IP addresses were used to circumvent rate-limiting. Thankfully that even with that many unique IPs and presumably a few tries per IP, you still only have enough tries to crack weak passwords.
- null_ptr 13y agoInteresting, my account's Security History shows a few failed login attempts in the last 3 days from Eastern Europe and Southeast Asia, and my account is not even popular.
- doughj3 13y agoYour comment prodded me to check my own Security History, and I have five failed login attempts within the past 3 days from unrecognized IPs also on a not-popular account.
- city41 13y agoI do as well. One from Korea and one from Venezuela.
- mikexstudios 13y agoI have 12 failed attempts in the past 4 days, and I don't have a popular account either.
- allochthon 13y agoYep -- in my case from Turkey, France and Venezuela. And I'm in California.
- Wingman4l7 13y agoA friend and I both showed 6 login attempts from unique IPs and neither one of us are very active. Seems like they hit a lot of people.
- imdsm 13y agoThey did the OAuth token with the Ripple give away 16 days ago, and before that, I had no failed attempts, just a single successful attempt. I too used the same password for a few sites.
- oneeyedpigeon 13y agoI've seen a small amount of suspicious activity (possibly 3 failed logins that weren't mine); I'm wondering how relevant various attributes of the username are. I'm starting to move to unique usernames for various services: not anything vastly secure, but something that's at least harder to automatically cross-reference. Does anyone know if using much longer usernames is a worthwhile investment?
- deleted 13y ago[deleted]
- captn3m0 13y agoIf these attackers had tried targeted brute-force on some limited accounts, they might have been successful without tripping over the GitHub security team. Nonetheless, kudos to GitHub for handling this perfectly.
- benaiah 13y agoHad five attempts over the last 2 days, four from Venezuela and one from Bangladesh. All unique IPs.
- samweinberg 13y agoSame here. 5 attempts over the last 2 days all from unique IPs. Four from Venezuela and one from Beijing.
- uladzislau 13y agoCan Fail2ban http://www.fail2ban.org http://www.fail2ban.org help in this case?
- nobodyshere 13y agoNot really. Some ISP provide same external IP to multiple users and you have to take that into account. I think otherwise a good part of github's users would never be able to access it.
- cft 13y agoJust show captcha randomly on login, with the frequency proportional to login failure rate for an account.
- eliteraspberrie 13y agoOnly allow logins from country/continent: X With a feature like that, if an IP address from country C attempts to log in to accounts of users in separate countries A and B, they are quickly spotted.
- itchitawa 13y agoGmail does something a bit more sophisticated than this but it's a real pain trying to check your mail from the airport in another country when your phone doesn't work either to confirm that way. Also annoying for VPN users who may appear to be in another country.
- ismail 13y agoSingle failed login attempt from china. Though could this be any way related to the adobe leak? If you have the list of emails and password, you could try a bunch of commonly used services and see if that works.
- objclxt 13y agoGitHub do say in their post: > These addresses were used to slowly brute force weak passwords or passwords used on multiple sites. ..."multiple sites" could possibly refer to a compromised list, like Adobe? Of course, it doesn't have to be Adobe - Macrumors was compromised recently, etc etc.
- arasmussen 13y agoI'd love to know just how weak "weak" is. Something like [A-Za-z0-9]+ and <= 6 characters, or [a-z]+ and <= 8 characters?
- FiloSottile 13y agoHere, it is weak as in "password", "qwerty" or "{your Lifehacker leaked password}"
- codygman 13y agomy password was \w{6}\d{2} and it was compromised.
- mh- 13y agowas the \w{6} github?
- codygman 13y agoLOL, luckily it was not. It wasn't a dictionary word.
- FiloSottile 13y agoDid you reuse that password somewhere else?
- ya 13y agoripple.. you bastard,.
- Wingman4l7 13y agoIt wasn't Ripple, it was someone trying to game their giveaway: https://news.ycombinator.com/item?id=6766293 https://news.ycombinator.com/item?id=6766293
- deleted 13y ago[deleted]
- fphilipe 13y agoConsidering that the code in a GitHub organization or in a repo with collaborators is only as safe as the weakest link in the chain of users that have access to it, it would be nice if the admin of that org/repo could set a policy that all members need to have 2-factor authentication activated before they get full access to the codebase. Enforcing strong and unique passwords is hard, but enforcing 2-factor is easy and the bump in added security is high. At least I would sleep better knowing that, for an attacker to access the codebase, brute forcing would not be possible.
- csmuk 13y agoEnforcing unique and strong passwords is not hard. We do it.
- fphilipe 13y agoHow do you enforce a unique password? With unique I mean that the user has not used that password for any other website.
- nilved 13y agoGenerating it for them.
- oneeyedpigeon 13y agohow do you make it memorable enough so they don't just write it down? passphrases?
- mdpopescu 13y agoWhat's the problem with writing it down? I periodically generate a strong random new password, write it down and put it in my wallet with my credit cards, until I type it enough times that I learned it. Writing it down and leaving it exposed in a public place, like taped to your monitor - bad. Writing it down and treating it like any other important asset - not that bad.
- welder 13y ago> This is a security log of important events involving your account. > 18 hours ago user.failed_login: Originated from 178.245.129.47 (Istanbul) > 3 days ago user.failed_login: Originated from 180.250.45.186 (Indonesia) > 3 days ago user.failed_login: Originated from 123.119.141.184 (China) Is this a distributed brute force attack against my account?
- masklinn 13y agoIt's part of the brute-force effort against all of github, not specifically your account. I have 13 such events logged.
- dbaupp 13y agoI see similar a thing; I'd guess that they just tried a few common passwords against millions of accounts, rather than targeting some specific accounts.
- Wingman4l7 13y agoI wonder why Github didn't publicly post the details behind the attack -- namely, that is was an attempt to game a Ripple (cryptocurrency) giveaway. They mentioned it in their "heads up Github user, your account was compromised" emails, apparently: https://news.ycombinator.com/item?id=6766293 https://news.ycombinator.com/item?id=6766293
- nilved 13y agoThat wasn't in my email.
- dm2 13y agoAlong with 2-factor auth, what about the option to block all IPs from outside of a certain country (if you live/work in the US, only allow US logins). This obviously won't work for everyone, but might prevent a decent amount of brute force successes.
- rythie 13y agoFacebook detects this when you move countries and makes you do a quiz about your friends pictures - though it can be pretty annoying [though I haven't seen it recently so maybe they've stopped].
- krlkr 13y agoI just dealt with this today with my own account using a proxy, quite a clever security approach IMHO
- nilved 13y agoThe attack must have been done over Tor. My account was flagged and locked but it's not reasonable to say the password was cracked. However, I do my day-to-day browsing over Tor and the matching IP addresses caused a false positive. Its worth mentioning, though, that the rate limiting is at the account level and not the IP level. When I was trying to get access to my account before the email was sent out, my account was locked and remained locked even after developing a new Tor circuit. How were the attackers able to circumvent the aggressive rate limiting? Three password attempts a minute is a generous estimate and it would take longer than the expected life of the universe to crack even a moderately secure password at that rate (my old password had 704 decillion permutations.) Perhaps some part of GitHub isn't being rate limited?
- ushi 13y ago>> The attack must have been done over Tor. Nope, none of the failed attempts on my account originate from a tor exit node.
- nilved 13y agoI only have Tor logins recorded and nothing indicates that my account was compromised, so one of the exit nodes I used must also have been used by the attackers. I guess it doesn't necessarily mean that the entire attack was done over Tor. Perhaps a zombie in the botnet was running it. :)
- imdsm 13y agoLooking at my security log, it looks like they gained access over two weeks ago. No failed login attempts, just a successful login. No brute-forcing about it. oauth_access.create: GitHub XRP Giveaway - 16 days ago user.login: Originated from 23.29.121.166 - 16 days ago
- andyhmltn 13y agoLogging into my account, I can see quite a few failed attempts from a variety of IP addresses. All of them are from the same ISP in Venezuela. Quite scary, but my password is 40+ characters long and I have 2FA enabled. How weird!
- Damin0u 13y agoI wish the weak password blacklist was public, so we can all implement password check like this easily, and maybe get rid of them forever (even if banning "chicken" as password is only a way to have "egg" popping up).
- shubhamjain 13y agoThis reminds me the #1 tip of web development: Never trust the user. I can't imagine there is a person out there who has all the time in the world to brute force accounts with common phrases with 40,000 proxies (or whatever). Seriously, is there anything worth gaining if you get hold of even say 100s of accounts.
- Wingman4l7 13y agoWell, first of all, it's very likely they used a botnet and some automated attack software. Secondly, there was a financial incentive[1] -- my back-of-the-napkin calculation was ~$15-25 per compromised account. That of course is ignoring secondary values like API keys, reused passwords allowing access to accounts on other sites, etc. [1]: https://news.ycombinator.com/item?id=6766293 https://news.ycombinator.com/item?id=6766293
- gambler 13y agoYou can spread malware through Open Source projects.
- cik 13y agoI'm very impressed by GitHub's response - what a prime example of how you should handle an intrusion attempt! 11/10 for style from an IT governance and disclosure point of view. They've successfully: identified the nature of the attack, notified customers in a polite manner, publicly disclosed the goings on, and exercised added paranoia (which in this case == security) by disabling related accounts. Kudos! The only thing they missed is disclosing that they're working with local law enforcement - something I'd presume they're doing. More interesting is the attempt. I frequently scan customer systems on their behalf, by spinning up clouds of resources to hammer their login APIs. By using Digital Ocean $0.05/hour boxes, and massive threading, tests tend to cost me ~$50/hour (yes, that's 1000 boxes orchestrated). Given the real world cost of cloud computing, and the ease of libraries such as libCloud (or ruby's: FOG), the cost of doing this in terms of time and real money has dropped dramatically.