Live data from Hacker News

370 Passwords You Can't Use On Twitter

techcrunch.com

11–19 of 19 posts

Re: 370 Passwords You Can't Use On Twitter

#12

Some of these are so unusual.. rush2112?

To all you sys admins out there: Is rush2112 really as common as some of these? I am a bit chagrined by its presence on this list as I have used that as a low security password for 10 years. In fact it is currently my password to HN!! (of course by the time you read this I will have changed it :P )

Re: 370 Passwords You Can't Use On Twitter

#14
post #3

This is a pretty silly question. Lists of most insecure passwords have been posted since the dark ages. Meanwhile, Twitter doesn't store passwords and can't analyze them (without going through contortions).

They could store plain text passwords plus a counter for each. Just so long as there's no connection to the users. They would not need that connection for this purpose.

Re: 370 Passwords You Can't Use On Twitter

#15
post #4
post #2

What would be interesting to know is if Twitter got this list from somewhere else, or if they actually analyze which passwords were most commonly chosen by its tens of millions of users in the past I thought it was the journalist's job to research, not the reader's. Would it be that hard to fire up an email to Twitter and say 'hey, this is Techcrunch, we have a question...'? It's not like this is urgent news and must…

In the New Model, it's good for a site like TC to leave obvious questions unanswered, or even a blatant error or two in the story. It triggers comments and followup stories!

Simply put, in the New Model editorial professionalism is just as irrelevant as in the Old Model.

Like the old model, editorial professionalism is simply to bring return customers and provide a larger market base to your advertisers.

Re: 370 Passwords You Can't Use On Twitter

#16
post #3

This is a pretty silly question. Lists of most insecure passwords have been posted since the dark ages. Meanwhile, Twitter doesn't store passwords and can't analyze them (without going through contortions).

They could store plain text passwords plus a counter for each. Just so long as there's no connection to the users. They would not need that connection for this purpose.

(a) This fairly qualifies as "contortions", and (b) if an enterprising blogger found out that they were doing this, they could construct a convincing post that this was a security vulnerability (for instance, through timing).

If you like, you can also suggest that they simply SHA1 passwords, and keep a database of well-known passwords and their SHA1 hashes. But again: a lot of effort for almost no benefit. The list-of-worst-passwords is a very solved problem.

Post reply on HN