Live data from Hacker News

Passwords for 32M Twitter accounts may have been hacked and leaked

techcrunch.com

61–70 of 199 posts

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#61
post #43

Earlier quoted context omitted.

How can you say it doesn't scale? You just need to spin up a cluster that is powerful enough to get down to let's say a week. The cost of this would be a joke for a company / institution of a certain size.

1 week only tests 1 password. It would have to run for years to get a decent set of results. I don't see how a company can afford all that hardware and power to do something that is illegal to begin with. How do they monetize it to get a return?

You just need to target certain accounts, no need for all.

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#62
post #43

Earlier quoted context omitted.

How can you say it doesn't scale? You just need to spin up a cluster that is powerful enough to get down to let's say a week. The cost of this would be a joke for a company / institution of a certain size.

1 week only tests 1 password. It would have to run for years to get a decent set of results. I don't see how a company can afford all that hardware and power to do something that is illegal to begin with. How do they monetize it to get a return?

And don't forget, that every 18 months, the amount of processing power you get for a modest price, doubles.

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#63
post #43
post #42

Earlier quoted context omitted.

An i7 laptop. But even if you use an 18 cores server, it doesn't really change the point. It might take a month instead of a year. But it still doesn't scale, even to only check the most common passwords.

How can you say it doesn't scale? You just need to spin up a cluster that is powerful enough to get down to let's say a week. The cost of this would be a joke for a company / institution of a certain size.

It does technically scale, just like everything else :)

But I think the parent's point was that this compute time only lets you check one password against one account. All you can do, after this compute time, is state that "'monkey' is/ is not the correct password for @iagooar's account".

Those results can't be used to check other accounts (because they're salted) so this approach doesn't really scale well at all. It might, for a huge adversary (state-scale) allow a single password to be cracked in a reasonable timeframe, iff it's relatively simple password.

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#65
post #22

Twitter also does 2-Factor Auth. If you value your Twitter account, in addition to changing your password (which hopefully is unique amongst your accounts), also activate 2FA.

Was just trying to set this up, and not great (IMHO). The feature is called "Login Verification", I think, and it's only SMS based, no Google Authenticator / Authy style one-time password... Also, it was saying I needed to verify my email address before that feature can be used, but there was no option to verify the email address that is used since I've registered almost a decade ago... Had to change my email (used t…

Curious, why is SMS-based auth a downside in your opinion? I prefer to use SMS-based 2FA where available, as you can always pop the sim card into whatever device you have on hand and receive the code. As opposed to smartphone app, where you are tied to a particular device being available and in working order.

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#66
post #42

Earlier quoted context omitted.

> it can easily take a second to check a hash On what hardware?

An i7 laptop. But even if you use an 18 cores server, it doesn't really change the point. It might take a month instead of a year. But it still doesn't scale, even to only check the most common passwords.

https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27...

107 kHashes/second/machine for bcrypt in default settings (which probably many sites will use).

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#67

Earlier quoted context omitted.

Just to add, Twitter's 2FA is "broken" because it only has SMS support. You cannot configure an app and I don't want to give Twitter my phone number.

While that's annoying, I wouldn't call lit broken. Most 2FA-enabled services I know want a phone number first, including Google (and from what I remember Facebook as well). If you're worried about your privacy, which is understandable, buy a prepaid sim card, a cheap phone and use it only for your 2FA accounts. Not sure about the US, but in my country prepaid GSM sim cards are cheap and you don't have to give away yo…

> I wouldn't call lit broken

It's vulnerable to social engineering of your cell provider's customer support line, for one. It's happened before [1].

[1] http://gizmodo.com/how-hackers-reportedly-side-stepped-gmail...

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#68
post #46

Earlier quoted context omitted.

RTFA. Twitter didn't get hacked. Browser malware screen-scraped the passwords.

I did RTFA. Do you think a typical end user is going to care the technicalities of how their password might have been leaked? I certainly don't. The takeaway for me is that (yet) another website I entered personal information has leaked it - regardless of how this happened it further damages the trust I have for Twitter. Had I never used Twitter all of this would be a non-event. Please do tell me if you think I'm bei…

The takeaway for me is that (yet) another website I entered personal information has leaked it

Well, I think it's quite difficult to argue that. If you had a keylogger installed on your machine – apparently the case here – in what way did the website leak your personal information? Wasn't it the browser's fault?

I do think it's pretty illogical to complain about Twitter being vulnerable, if this leak was caused by screen-scraping malware in a browser. It's not something that Twitter can really defend against, beyond measures like 2FA.

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#69

Earlier quoted context omitted.

I did RTFA. Do you think a typical end user is going to care the technicalities of how their password might have been leaked? I certainly don't. The takeaway for me is that (yet) another website I entered personal information has leaked it - regardless of how this happened it further damages the trust I have for Twitter. Had I never used Twitter all of this would be a non-event. Please do tell me if you think I'm bei…

The takeaway for me is that (yet) another website I entered personal information has leaked it Well, I think it's quite difficult to argue that. If you had a keylogger installed on your machine – apparently the case here – in what way did the website leak your personal information? Wasn't it the browser's fault? I do think it's pretty illogical to complain about Twitter being vulnerable, if this leak was caused by sc…

Thanks for the explanation, makes sense. Still I wonder how many non-techies will simply read "Twitter hacked" and devalue the Twitter brand in their minds.

Re: Passwords for 32M Twitter accounts may have been hacked and leaked

#70

Earlier quoted context omitted.

I did RTFA. Do you think a typical end user is going to care the technicalities of how their password might have been leaked? I certainly don't. The takeaway for me is that (yet) another website I entered personal information has leaked it - regardless of how this happened it further damages the trust I have for Twitter. Had I never used Twitter all of this would be a non-event. Please do tell me if you think I'm bei…

It is also important to note that Russian accounts seem to be affected, which might indicate that only Russian browsers have been affected. Furthermore, if your browser is infected, a lot worse things can happen then having your Twitter account compromised (e.g. access to your PayPal, bank and even your personal files).

True that - good points well made.
Post reply on HN