Live data from Hacker News

43M passwords hacked in Last.fm breach

techcrunch.com

41–50 of 172 posts

Re: 43M passwords hacked in Last.fm breach

#41

I would like to see websites make password changing a simple and standardized API call. That way integration with things like 1password will allow it to automatically change the password with each login. Or I can schedule them all to be updated every day, etc. This drastically reduces the amount of valid logins from a dump that's even just a few days old. 2factor is simply not enough (though I still want it for impor…

>I would like to see websites make password changing a simple and standardized API call. That way integration with things like 1password will allow it to automatically change the password with each login. There isn't really a need for a standardized API it would make things easier but if 1password wanted it's not a very hard thing to do without it. All you need is to do an HTTP request to change the password most sit…

LastPass does this. I actually used it about a year ago to automatically change the passwords on about three dozen sites. It failed on two pages that had recently been updated. It's a very useful feature though.

Re: 43M passwords hacked in Last.fm breach

#42

Earlier quoted context omitted.

Password managers already do that, they just check for password type field and the site. Keepass does that pretty sure all the others also do. But again what problem are you trying to solve? using password managers is easy as pie today including automating signup and generating passwords, most people do not use them.

I started using LastPass just the other day because the recent news made me nervous. It's NOT easy. The interfaces are clunky. I have to pay to get some basic features like browser plugin. There's a lot of false positives (it suggests me sometimes to save a password even if the field is not for passwords.) Generating secure passwords is hard because some sites validate length and charset only serverside and the poor…

I'm using lastpass and I haven't had to pay for the browser plugin.

I've been using lastpass for the past year or so, and I've had no real issues with it ergonomics-wise. I can't even think of any sites off the top of my head that have given false positives.

It does seem painfully slow and unresponsive sometimes though, which isn't ideal. It's slow enough to disrupt my flow more than just typing in the same password for every website.

Re: 43M passwords hacked in Last.fm breach

#43

We really need some laws around this... Prison time for web developers that store passwords insecurely, and substantial fines for anyone whose password can be brute forced from one of these leaks.

> substantial fines for anyone whose password can be brute forced from one of these leaks

Isn't that rather like fining someone for being too weak to fight back when assaulted?

Re: 43M passwords hacked in Last.fm breach

#44

We really need some laws around this... Prison time for web developers that store passwords insecurely, and substantial fines for anyone whose password can be brute forced from one of these leaks.

Wow - extreme! I reckon we have a few more cracks at solving this problem as an industry before we resort to locking up junior devs.

Re: 43M passwords hacked in Last.fm breach

#45

I would like to see websites make password changing a simple and standardized API call. That way integration with things like 1password will allow it to automatically change the password with each login. Or I can schedule them all to be updated every day, etc. This drastically reduces the amount of valid logins from a dump that's even just a few days old. 2factor is simply not enough (though I still want it for impor…

Automatic password changing would be a mess if you ever got locked out of your password manager, combined with the fact that if the protocol for password changing was to be breached, you'd be locked out of that account as well.

The protocol isn't any different than it is today you need to know the account and the current password, there isn't anything more to breach then today it's no different than any password change form.

If you get locked out of your password manager you are already fucked.

And in any case It doesn't prevent users from reseting a password manually directly on each site.

Re: 43M passwords hacked in Last.fm breach

#46

Earlier quoted context omitted.

As someone who has very strong feelings about sites not letting me choose secure passwords, or storing them insecurely...no. Fines for storing passwords insecurely and getting breached, sure. This is already handled by PCI/HIPAA, but could definitely stand to be improved. Prison time? There's no possible way that would end well. Fines for "anyone whose password can be brute forced from one of these leaks"? So that me…

> So that means 80% of people out there would be given "substantial fines". Not going to happen. How is that any different than giving speeding tickets? If you behave recklessly in a way that puts others at risk, you should have to make restitution to society.

Hmm not sure I understand your reasoning here.. You don't think there's a difference between speeding and choosing a weak password for a site like last.fm? The latter might be a bit silly, but how does it put others at risk?

Re: 43M passwords hacked in Last.fm breach

#48

It looks like our current approach isn't working. What if we had each site publish its login/registration endpoints in a URL, e.g. .well-known/loginurls? Then the password manager could detect you're trying to register or log in and log you in itself, generating your password in the process. Why aren't logins machine-accessible yet?

I made a similar proposal 3 years ago and submitted it to HN. There was a bit of interest, but a lot of people back then seemed to assume that passwords were going the way of the dinosaur anyway so why bother?

https://news.ycombinator.com/item?id=5743057

Now that Persona is defunct and there is no privacy-respecting alternative in sight, perhaps we can finally acknowledge the truth that passwords are here to stay for the foreseeable future.

Also, using .well-known looks better than what I originally proposed (header or tag). For maximim compatibility with existing systems, there should be an option for this URL to respond with the actual login URL as well as any restrictions on the password format (length > 6, numbers > 1, symbols > 1, disallowed symbol list, etc.)

Re: 43M passwords hacked in Last.fm breach

#49

Earlier quoted context omitted.

> So that means 80% of people out there would be given "substantial fines". Not going to happen. How is that any different than giving speeding tickets? If you behave recklessly in a way that puts others at risk, you should have to make restitution to society.

Hmm not sure I understand your reasoning here.. You don't think there's a difference between speeding and choosing a weak password for a site like last.fm? The latter might be a bit silly, but how does it put others at risk?

With the Dropbox hack for example, the reason they got hacked is because one of their employees reused a password, presumably from another site that got hacked. So that's one vector, where every time a site gets hacked, people using weak passwords (and reusing them) create the risk of future hacks.

But more generally, exposing your account credentials allows others to impersonate you and potentially scam others, expose the data of others, etc. In the case of Last.fm there obviously isn't a ton of potential for abuse directly, other than maybe firing off fake song plays to pocket the royalties, but the potential for greater harm exists in the general case. E.g. consider the enormous percentage of credit card transactions that are fraudulent, largely because of scammers using PII that's stolen in these large scale hacks. That absolutely effects the fees and interest rates for everyone else using banks in any way, so even if your own identity isn't stolen you're absolutely still affected.

And even in some hypothetical scenario where the only person harmed would be the person using the weak password, there is still precedent for regulation because we have laws requiring people to wear bike helmets, preventing kids from smoking, etc.

Re: 43M passwords hacked in Last.fm breach

#50
post #24

Earlier quoted context omitted.

Password managers already do that, they just check for password type field and the site. Keepass does that pretty sure all the others also do. But again what problem are you trying to solve? using password managers is easy as pie today including automating signup and generating passwords, most people do not use them.

Who wants to be helping every relative set them up and adding to the unpaid support load? So they get mentioned in passing and then people think "Yes, I should do that" and never bother. Same thing happens with backups.

[deleted]
Post reply on HN