Earlier quoted context omitted.
How can you say it doesn't scale? You just need to spin up a cluster that is powerful enough to get down to let's say a week. The cost of this would be a joke for a company / institution of a certain size.
1 week only tests 1 password. It would have to run for years to get a decent set of results. I don't see how a company can afford all that hardware and power to do something that is illegal to begin with. How do they monetize it to get a return?
Passwords for 32M Twitter accounts may have been hacked and leaked
61–70 of 199 posts
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#62Earlier quoted context omitted.
How can you say it doesn't scale? You just need to spin up a cluster that is powerful enough to get down to let's say a week. The cost of this would be a joke for a company / institution of a certain size.
1 week only tests 1 password. It would have to run for years to get a decent set of results. I don't see how a company can afford all that hardware and power to do something that is illegal to begin with. How do they monetize it to get a return?
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#63Earlier quoted context omitted.
An i7 laptop. But even if you use an 18 cores server, it doesn't really change the point. It might take a month instead of a year. But it still doesn't scale, even to only check the most common passwords.
How can you say it doesn't scale? You just need to spin up a cluster that is powerful enough to get down to let's say a week. The cost of this would be a joke for a company / institution of a certain size.
But I think the parent's point was that this compute time only lets you check one password against one account. All you can do, after this compute time, is state that "'monkey' is/ is not the correct password for @iagooar's account".
Those results can't be used to check other accounts (because they're salted) so this approach doesn't really scale well at all. It might, for a huge adversary (state-scale) allow a single password to be cracked in a reasonable timeframe, iff it's relatively simple password.
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#64Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#65Twitter also does 2-Factor Auth. If you value your Twitter account, in addition to changing your password (which hopefully is unique amongst your accounts), also activate 2FA.
Was just trying to set this up, and not great (IMHO). The feature is called "Login Verification", I think, and it's only SMS based, no Google Authenticator / Authy style one-time password... Also, it was saying I needed to verify my email address before that feature can be used, but there was no option to verify the email address that is used since I've registered almost a decade ago... Had to change my email (used t…
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#66Earlier quoted context omitted.
> it can easily take a second to check a hash On what hardware?
An i7 laptop. But even if you use an 18 cores server, it doesn't really change the point. It might take a month instead of a year. But it still doesn't scale, even to only check the most common passwords.
107 kHashes/second/machine for bcrypt in default settings (which probably many sites will use).
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#67Earlier quoted context omitted.
Just to add, Twitter's 2FA is "broken" because it only has SMS support. You cannot configure an app and I don't want to give Twitter my phone number.
While that's annoying, I wouldn't call lit broken. Most 2FA-enabled services I know want a phone number first, including Google (and from what I remember Facebook as well). If you're worried about your privacy, which is understandable, buy a prepaid sim card, a cheap phone and use it only for your 2FA accounts. Not sure about the US, but in my country prepaid GSM sim cards are cheap and you don't have to give away yo…
It's vulnerable to social engineering of your cell provider's customer support line, for one. It's happened before [1].
[1] http://gizmodo.com/how-hackers-reportedly-side-stepped-gmail...
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#68Earlier quoted context omitted.
RTFA. Twitter didn't get hacked. Browser malware screen-scraped the passwords.
I did RTFA. Do you think a typical end user is going to care the technicalities of how their password might have been leaked? I certainly don't. The takeaway for me is that (yet) another website I entered personal information has leaked it - regardless of how this happened it further damages the trust I have for Twitter. Had I never used Twitter all of this would be a non-event. Please do tell me if you think I'm bei…
Well, I think it's quite difficult to argue that. If you had a keylogger installed on your machine – apparently the case here – in what way did the website leak your personal information? Wasn't it the browser's fault?
I do think it's pretty illogical to complain about Twitter being vulnerable, if this leak was caused by screen-scraping malware in a browser. It's not something that Twitter can really defend against, beyond measures like 2FA.
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#69Earlier quoted context omitted.
I did RTFA. Do you think a typical end user is going to care the technicalities of how their password might have been leaked? I certainly don't. The takeaway for me is that (yet) another website I entered personal information has leaked it - regardless of how this happened it further damages the trust I have for Twitter. Had I never used Twitter all of this would be a non-event. Please do tell me if you think I'm bei…
The takeaway for me is that (yet) another website I entered personal information has leaked it Well, I think it's quite difficult to argue that. If you had a keylogger installed on your machine – apparently the case here – in what way did the website leak your personal information? Wasn't it the browser's fault? I do think it's pretty illogical to complain about Twitter being vulnerable, if this leak was caused by sc…
Re: Passwords for 32M Twitter accounts may have been hacked and leaked
#70Earlier quoted context omitted.
I did RTFA. Do you think a typical end user is going to care the technicalities of how their password might have been leaked? I certainly don't. The takeaway for me is that (yet) another website I entered personal information has leaked it - regardless of how this happened it further damages the trust I have for Twitter. Had I never used Twitter all of this would be a non-event. Please do tell me if you think I'm bei…
It is also important to note that Russian accounts seem to be affected, which might indicate that only Russian browsers have been affected. Furthermore, if your browser is infected, a lot worse things can happen then having your Twitter account compromised (e.g. access to your PayPal, bank and even your personal files).