Live data from Hacker News

Passwords for 32M Twitter accounts may have been hacked and leaked

techcrunch.com

51–60 of 199 posts

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#51
post #43
post #42

Earlier quoted context omitted.

An i7 laptop. But even if you use an 18 cores server, it doesn't really change the point. It might take a month instead of a year. But it still doesn't scale, even to only check the most common passwords.

How can you say it doesn't scale? You just need to spin up a cluster that is powerful enough to get down to let's say a week. The cost of this would be a joke for a company / institution of a certain size.

1 week only tests 1 password. It would have to run for years to get a decent set of results. I don't see how a company can afford all that hardware and power to do something that is illegal to begin with. How do they monetize it to get a return?

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#52
post #46

I didn't need another reason to dislike Twitter but this puts another nail in their coffin, for me at least. It seems the two platforms I derive the least amount of value from (Twitter and Linked In) are the most vulnerable to hackers and leaked passwords. I was caught up in the Linked In password debacle recently and now have my e-mail address in the haveIbeenpwned.com database - thanks Linked In. I wonder if I'll g…

RTFA. Twitter didn't get hacked. Browser malware screen-scraped the passwords.

I did RTFA.

Do you think a typical end user is going to care the technicalities of how their password might have been leaked? I certainly don't.

The takeaway for me is that (yet) another website I entered personal information has leaked it - regardless of how this happened it further damages the trust I have for Twitter.

Had I never used Twitter all of this would be a non-event.

Please do tell me if you think I'm being illogical - I'm all ears.

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#54

Earlier quoted context omitted.

While that's annoying, I wouldn't call lit broken. Most 2FA-enabled services I know want a phone number first, including Google (and from what I remember Facebook as well). If you're worried about your privacy, which is understandable, buy a prepaid sim card, a cheap phone and use it only for your 2FA accounts. Not sure about the US, but in my country prepaid GSM sim cards are cheap and you don't have to give away yo…

To me that's broken because if I travel, change numbers, or have wifi but no cell coverage, I can't access my account.

By that logic, it is also also broken because if you don't have access to your phone or the Google Authtenticator app or phone OS is malfunctioning, you can't access your account.

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#55

Earlier quoted context omitted.

Just to add, Twitter's 2FA is "broken" because it only has SMS support. You cannot configure an app and I don't want to give Twitter my phone number.

While that's annoying, I wouldn't call lit broken. Most 2FA-enabled services I know want a phone number first, including Google (and from what I remember Facebook as well). If you're worried about your privacy, which is understandable, buy a prepaid sim card, a cheap phone and use it only for your 2FA accounts. Not sure about the US, but in my country prepaid GSM sim cards are cheap and you don't have to give away yo…

If you do so, please be sure to check how often you have to top up the number so it isn't "freed". The prepaid provider I used to use had me top it up every 6 months for at least 5€ ($7 at the time), to keep my number. I can't really blame them, though because they also have to pay for the numbers.

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#56
post #46

Earlier quoted context omitted.

RTFA. Twitter didn't get hacked. Browser malware screen-scraped the passwords.

I did RTFA. Do you think a typical end user is going to care the technicalities of how their password might have been leaked? I certainly don't. The takeaway for me is that (yet) another website I entered personal information has leaked it - regardless of how this happened it further damages the trust I have for Twitter. Had I never used Twitter all of this would be a non-event. Please do tell me if you think I'm bei…

It is also important to note that Russian accounts seem to be affected, which might indicate that only Russian browsers have been affected.

Furthermore, if your browser is infected, a lot worse things can happen then having your Twitter account compromised (e.g. access to your PayPal, bank and even your personal files).

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#60
post #5

Question: From my understanding bcrypt is designed for security even when the hashed data is leaked. Each piece of data is uniquely salted and hashed to perhaps varying degrees of difficulty. So for a thought experiment, let's say a site made the password column of their user database public. Given an entirely public password column, even with associated usernames, would this have any use or decrease the security of…

How can a salt change on every encoding?

There has to be a reference point, no?

Post reply on HN