Earlier quoted context omitted.
Easy. CBS bought them late 2007. Dev and updates pretty much stopped. They limited tracks you could play directly. Then they killed radio. I'm really sad to see it die, it was better at introducing me to new artists than any other service before or since, and the radio was brilliant.
Oh you must have left awhile ago then. I agree they ruined the best music discovery service on the web, but even without it the site was dated but functional.. until last year. Last year CBS decided the whippersnappers needed a redesign and took out around 80% of the features and put the site into a perpetual beta state.
43M passwords hacked in Last.fm breach
31–40 of 172 posts
Re: 43M passwords hacked in Last.fm breach
#32I would like to see websites make password changing a simple and standardized API call. That way integration with things like 1password will allow it to automatically change the password with each login. Or I can schedule them all to be updated every day, etc. This drastically reduces the amount of valid logins from a dump that's even just a few days old. 2factor is simply not enough (though I still want it for impor…
Re: 43M passwords hacked in Last.fm breach
#33I would like to see websites make password changing a simple and standardized API call. That way integration with things like 1password will allow it to automatically change the password with each login. Or I can schedule them all to be updated every day, etc. This drastically reduces the amount of valid logins from a dump that's even just a few days old. 2factor is simply not enough (though I still want it for impor…
>I would like to see websites make password changing a simple and standardized API call. That way integration with things like 1password will allow it to automatically change the password with each login. There isn't really a need for a standardized API it would make things easier but if 1password wanted it's not a very hard thing to do without it. All you need is to do an HTTP request to change the password most sit…
You would benefit from open-sourcing them, so others could help you keep up with websites changing.
Re: 43M passwords hacked in Last.fm breach
#34We really need some laws around this... Prison time for web developers that store passwords insecurely, and substantial fines for anyone whose password can be brute forced from one of these leaks.
What a terrible idea.
Re: 43M passwords hacked in Last.fm breach
#35Earlier quoted context omitted.
Easy. CBS bought them late 2007. Dev and updates pretty much stopped. They limited tracks you could play directly. Then they killed radio. I'm really sad to see it die, it was better at introducing me to new artists than any other service before or since, and the radio was brilliant.
Oh you must have left awhile ago then. I agree they ruined the best music discovery service on the web, but even without it the site was dated but functional.. until last year. Last year CBS decided the whippersnappers needed a redesign and took out around 80% of the features and put the site into a perpetual beta state.
Was mad about that as Last radio was my first choice for work listening.
The site was dated as they were frozen in 2008 - After CBS bought them there was one update very soon after then the site didn't change at all until last year. Minor updates and bug fixes only.
As for the update last year, pretty and vacant, doesn't bring back the things I loved about the site, but lets me see lots of pretty graphs of things I'm not interested in. I took a look at libre fm after that, but that's even more abandoned.
Re: 43M passwords hacked in Last.fm breach
#36I would like to see websites make password changing a simple and standardized API call. That way integration with things like 1password will allow it to automatically change the password with each login. Or I can schedule them all to be updated every day, etc. This drastically reduces the amount of valid logins from a dump that's even just a few days old. 2factor is simply not enough (though I still want it for impor…
Re: 43M passwords hacked in Last.fm breach
#37We really need some laws around this... Prison time for web developers that store passwords insecurely, and substantial fines for anyone whose password can be brute forced from one of these leaks.
Fines for storing passwords insecurely and getting breached, sure. This is already handled by PCI/HIPAA, but could definitely stand to be improved. Prison time? There's no possible way that would end well.
Fines for "anyone whose password can be brute forced from one of these leaks"? So that means 80% of people out there would be given "substantial fines". Not going to happen.
Re: 43M passwords hacked in Last.fm breach
#38We really need some laws around this... Prison time for web developers that store passwords insecurely, and substantial fines for anyone whose password can be brute forced from one of these leaks.
As someone who has very strong feelings about sites not letting me choose secure passwords, or storing them insecurely...no. Fines for storing passwords insecurely and getting breached, sure. This is already handled by PCI/HIPAA, but could definitely stand to be improved. Prison time? There's no possible way that would end well. Fines for "anyone whose password can be brute forced from one of these leaks"? So that me…
How is that any different than giving speeding tickets? If you behave recklessly in a way that puts others at risk, you should have to make restitution to society.
Re: 43M passwords hacked in Last.fm breach
#39Even still, I missed last.fm and probably a whole host of other ones that I'll never remember. Passwords are a goddamn nightmare.
Re: 43M passwords hacked in Last.fm breach
#40I would like to see websites make password changing a simple and standardized API call. That way integration with things like 1password will allow it to automatically change the password with each login. Or I can schedule them all to be updated every day, etc. This drastically reduces the amount of valid logins from a dump that's even just a few days old. 2factor is simply not enough (though I still want it for impor…
>I would like to see websites make password changing a simple and standardized API call. That way integration with things like 1password will allow it to automatically change the password with each login. There isn't really a need for a standardized API it would make things easier but if 1password wanted it's not a very hard thing to do without it. All you need is to do an HTTP request to change the password most sit…
[1] https://blog.lastpass.com/2014/12/introducing-auto-password-...