How we cracked millions of Ashley Madison passwords
cynosureprime.blogspot.com
How we cracked millions of Ashley Madison passwords
1–10 of 173 posts
Re: How we cracked millions of Ashley Madison passwords
#2Re: How we cracked millions of Ashley Madison passwords
#3Re: How we cracked millions of Ashley Madison passwords
#4I know, password reset keys are as bad as login keys, but usually they expire after a certain time frame.
F*ck login keys.
Re: How we cracked millions of Ashley Madison passwords
#5tl;dr they had a bad implementation and used md5 previously
Re: How we cracked millions of Ashley Madison passwords
#6I abandon any sites which give me direct logins via URLs sent over plain text emails. I know, password reset keys are as bad as login keys, but usually they expire after a certain time frame. F*ck login keys.
They were able to create an account and subscribe to the site without ever verifying the email, so for a week or so I was getting notifications sent to me without any way to unsubscribe from the email.
Clicking any of the links in the email signed me in as the user and gave me full access to their account and billing information. I ended up going into their account and turning off all email notifications to make the emails stop.
Edit: Just checked my trash folder and an email sent on the 8th of August still contained valid login keys to access the account.
Re: How we cracked millions of Ashley Madison passwords
#7e: Downvoting questions is mean. FWIW I always use bcrypt.
Re: How we cracked millions of Ashley Madison passwords
#8Re: How we cracked millions of Ashley Madison passwords
#9What's the risk of using plaintext passwords if we assume every user is employing long, random, unique passwords? This has always seemed like a non-issue to me because I've been using a password manager for a half-decade. e: Downvoting questions is mean. FWIW I always use bcrypt.
Re: How we cracked millions of Ashley Madison passwords
#10What's the risk of using plaintext passwords if we assume every user is employing long, random, unique passwords? This has always seemed like a non-issue to me because I've been using a password manager for a half-decade. e: Downvoting questions is mean. FWIW I always use bcrypt.