Live data from Hacker News

43M passwords hacked in Last.fm breach

techcrunch.com

61–70 of 172 posts

Re: 43M passwords hacked in Last.fm breach

#61
post #58

Man, I'm getting desensitized to the enormous numbers of accounts whose information gets leaked when a platform gets hacked. 43 million here, 68 million there. I'm semi-joking, but at this point it's almost like I need Facebook or Google level hacks (multiple hundred millions or billions) to actually think, "This is huge ."

I've been thinking that for a while, but also how come it's never me? I've had accounts with several hacked systems and sure I try to have pretty strong passwords but... I appear to be safe every time. Famous last words maybe, but then I'll just change my password?

You may appear safe but you never know... Services like Google and Facebook are pretty proactive about making sure unknown users can't access your account easily -- meaning that if someone from Thailand tried to access your account when you usually use it in the US from an unknown device, it'll generally not allow the login. But other services aren't as proactive and may be compromised, so it's definitely better to be safe. The best way is to use unique passwords for every service (or use OAuth with a service provider you trust), and a simple way to do that is with a password manager.

I personally recommend 1password, because they haven't had vulnerability issues like LastPass and don't store passwords in their cloud, but they store it in "your" cloud, e.g. iCloud, Dropbox, and it works very well on iPhone. But at the minimum just using a separate password for everything is the best way to mitigate these kinds of issues.

Re: 43M passwords hacked in Last.fm breach

#62

This is practically a startup, a service that just monitors and automatically updates your passwords as they get leaked over time.

1Password has a feature called Watchtower that can tell you if your password for each site is vulnerable.

Unfortunately it triggers any site that it doesn't explicitly know wasn't affected by heartbleed, which makes it trigger that vast majority of my passwords. This renders it more or less useless :(

Re: 43M passwords hacked in Last.fm breach

#64
post #53

Regular reminder that new users in general don't care at all about the security of your site. Most of your signups are not going to generate and store a secure password "just to try you out", as evidenced by the most common password here "123456". If you force people to signup to try your site/app, many (most?) of them are going to use a crap password. If you're _lucky_ that'll be 123456, and not their email/facebook…

why should users care ? what makes you think it's our job to make them care, we built another shitty system, it's not the users fault, asking them repeatedly to do something proven by cognitive science to be very challenging for most is just dumbness incarnate....

Re: 43M passwords hacked in Last.fm breach

#65
post #7

Earlier quoted context omitted.

How is Last.fm one of your favorite sites after that horrible redesign that erased tons of user-generated content?

Because it still does exactly what I want it to do, and what I've wanted it to do since I signed up in 2004, which is keep logs of every song that I listen to. The user-generated content side of it was added after I signed up (I think?) so I don't see how I could really miss it. 230K songs since 2004. http://www.last.fm/user/ryxxui

I'm annoyed that I didn't keep using it consistently. I even had it tracking usage from an offline iRiver H340 MP3 player - at the end of the day, I'd upload a database from Rockbox.

http://www.last.fm/user/voltagex

Re: 43M passwords hacked in Last.fm breach

#66

Earlier quoted context omitted.

Hmm not sure I understand your reasoning here.. You don't think there's a difference between speeding and choosing a weak password for a site like last.fm? The latter might be a bit silly, but how does it put others at risk?

With the Dropbox hack for example, the reason they got hacked is because one of their employees reused a password, presumably from another site that got hacked. So that's one vector, where every time a site gets hacked, people using weak passwords (and reusing them) create the risk of future hacks. But more generally, exposing your account credentials allows others to impersonate you and potentially scam others, expo…

[deleted]

Re: 43M passwords hacked in Last.fm breach

#68
post #7

Earlier quoted context omitted.

How is Last.fm one of your favorite sites after that horrible redesign that erased tons of user-generated content?

Because it still does exactly what I want it to do, and what I've wanted it to do since I signed up in 2004, which is keep logs of every song that I listen to. The user-generated content side of it was added after I signed up (I think?) so I don't see how I could really miss it. 230K songs since 2004. http://www.last.fm/user/ryxxui

You might be interested in https://libre.fm/ if you aren't confident about the future of Last.fm. It can be used as a drop-in replacement to track your music plays.

Re: 43M passwords hacked in Last.fm breach

#70

It would be nice if the EU would do something useful like require all sites to hash salted passwords and prohibit the use of weak hashes for new accounts. Instead we get the ridiculous cookie nag.

How would you regulate that? Wouldn't that suggest that the EU would have some sort of access to private back-ends in order to check?
Post reply on HN