Earlier quoted context omitted.
An i7 laptop. But even if you use an 18 cores server, it doesn't really change the point. It might take a month instead of a year. But it still doesn't scale, even to only check the most common passwords.
How can you say it doesn't scale? You just need to spin up a cluster that is powerful enough to get down to let's say a week. The cost of this would be a joke for a company / institution of a certain size.
Passwords for 32M Twitter accounts may have been hacked and leaked
51–60 of 199 posts
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#52I didn't need another reason to dislike Twitter but this puts another nail in their coffin, for me at least. It seems the two platforms I derive the least amount of value from (Twitter and Linked In) are the most vulnerable to hackers and leaked passwords. I was caught up in the Linked In password debacle recently and now have my e-mail address in the haveIbeenpwned.com database - thanks Linked In. I wonder if I'll g…
RTFA. Twitter didn't get hacked. Browser malware screen-scraped the passwords.
Do you think a typical end user is going to care the technicalities of how their password might have been leaked? I certainly don't.
The takeaway for me is that (yet) another website I entered personal information has leaked it - regardless of how this happened it further damages the trust I have for Twitter.
Had I never used Twitter all of this would be a non-event.
Please do tell me if you think I'm being illogical - I'm all ears.
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#53Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#54Earlier quoted context omitted.
While that's annoying, I wouldn't call lit broken. Most 2FA-enabled services I know want a phone number first, including Google (and from what I remember Facebook as well). If you're worried about your privacy, which is understandable, buy a prepaid sim card, a cheap phone and use it only for your 2FA accounts. Not sure about the US, but in my country prepaid GSM sim cards are cheap and you don't have to give away yo…
To me that's broken because if I travel, change numbers, or have wifi but no cell coverage, I can't access my account.
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#55Earlier quoted context omitted.
Just to add, Twitter's 2FA is "broken" because it only has SMS support. You cannot configure an app and I don't want to give Twitter my phone number.
While that's annoying, I wouldn't call lit broken. Most 2FA-enabled services I know want a phone number first, including Google (and from what I remember Facebook as well). If you're worried about your privacy, which is understandable, buy a prepaid sim card, a cheap phone and use it only for your 2FA accounts. Not sure about the US, but in my country prepaid GSM sim cards are cheap and you don't have to give away yo…
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#56Earlier quoted context omitted.
RTFA. Twitter didn't get hacked. Browser malware screen-scraped the passwords.
I did RTFA. Do you think a typical end user is going to care the technicalities of how their password might have been leaked? I certainly don't. The takeaway for me is that (yet) another website I entered personal information has leaked it - regardless of how this happened it further damages the trust I have for Twitter. Had I never used Twitter all of this would be a non-event. Please do tell me if you think I'm bei…
Furthermore, if your browser is infected, a lot worse things can happen then having your Twitter account compromised (e.g. access to your PayPal, bank and even your personal files).
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#57I can finally recover my account!
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#58The real source, not this redundant media crap that buried the lede...
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#59I can finally recover my account!
"There are two types of companies, those that have been hacked, and those that don’t yet know they have been hacked."
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#60Question: From my understanding bcrypt is designed for security even when the hashed data is leaked. Each piece of data is uniquely salted and hashed to perhaps varying degrees of difficulty. So for a thought experiment, let's say a site made the password column of their user database public. Given an entirely public password column, even with associated usernames, would this have any use or decrease the security of…
There has to be a reference point, no?