Live data from Hacker News

43M passwords hacked in Last.fm breach

techcrunch.com

161–170 of 172 posts

Re: 43M passwords hacked in Last.fm breach

#161
post #120

Earlier quoted context omitted.

You seem obsessed with one implementation. Passwords themselves are obsolete. Actually the problem is already solved for at least a decade: Certificate based authentication. Browsers support it. Try StartSSl registration, for example.

Client certificates tie the user to a specific device, which is terrible. It just moves the problem back to "account recovery".

You can add multiple client sertificates to a single account for example in case of git hosting services. Why would it be impossible for other services?

Re: 43M passwords hacked in Last.fm breach

#162
post #76

Earlier quoted context omitted.

With the Dropbox hack for example, the reason they got hacked is because one of their employees reused a password, presumably from another site that got hacked. So that's one vector, where every time a site gets hacked, people using weak passwords (and reusing them) create the risk of future hacks. But more generally, exposing your account credentials allows others to impersonate you and potentially scam others, expo…

Should people be fined for not locking their doors?

No, but if they got robbed then probably they shouldn't get the full amount of their renters insurance.

Re: 43M passwords hacked in Last.fm breach

#163

We really need some laws around this... Prison time for web developers that store passwords insecurely, and substantial fines for anyone whose password can be brute forced from one of these leaks.

Or we could take an approach similar to the Philippines on drug dealers.

Re: 43M passwords hacked in Last.fm breach

#164

Earlier quoted context omitted.

Do you have any domain name (even if it has no webserver yet) or some pre-launch page to bookmark? Don't need such service now, but I had accidental necessity in past few years. (Also, please consider submitting it to HN when you go live.)

I bought the domain name smsprivacy.org but I could plausibly end up on a different one. I will submit a Show HN. Thanks :)

If you're after either a primary or backup SMS route or numbers (especially for the UK), I may be able to assist

Re: 43M passwords hacked in Last.fm breach

#166
post #79

> The number of passwords and the severity of the hack was not uncovered until today. The passwords were stored using unsalted MD5 hashing Enough said. > The most popular password pulled from the Last.fm database was 123456. Seriously, it’s 2016 people Sure, but the breach was in 2012 TechCrunch. Better article: http://www.leakedsource.com/blog/lastfm

> Sure, but the breach was in 2012 Even in 2012, storing passwords unsalted (and probably even hashed just once) was considered bad practice. As was MD5. Bad passwords being bad passwords also goes without saying. 123456 was never a good password.

You don't even need a breach to hack 123456, I expect it to be in every pentester's top20 first-tries (contingent on whatever profile they have on the target, obviously).

Re: 43M passwords hacked in Last.fm breach

#167
I know a real professional hacker who has worked for me twice in the past one month. He is very good at hacking anything concerning database, phone, social media and even credit report fixes. He offers legit services. He also helps to retrieve accounts that have been taken by hackers. Contact him at Alphafasttunnel247@cyberservices.com or text him at +1 646 480 9658

Re: 43M passwords hacked in Last.fm breach

#168
post #53

Regular reminder that new users in general don't care at all about the security of your site. Most of your signups are not going to generate and store a secure password "just to try you out", as evidenced by the most common password here "123456". If you force people to signup to try your site/app, many (most?) of them are going to use a crap password. If you're _lucky_ that'll be 123456, and not their email/facebook…

OpenID registration is the solution to this problem.

OpenID is dead thanks to OAuth. I hope IndieAuth could get some traction but the problem with it is that every user needs to have their own tld domain but many registrars and dns services don't even use two factor authentication.

Re: 43M passwords hacked in Last.fm breach

#169
post #6

Earlier quoted context omitted.

Wow! They had some great growth going on and it seemed to hit a wall hard around 2008-2009. Any idea why?

Easy. CBS bought them late 2007. Dev and updates pretty much stopped. They limited tracks you could play directly. Then they killed radio. I'm really sad to see it die, it was better at introducing me to new artists than any other service before or since, and the radio was brilliant.

It's tragic how corporate greed can kill such an awesome site. They wasn't even ashamed to ask for money in countries where they didn't had adverts while they were removing the features from its users.

Re: 43M passwords hacked in Last.fm breach

#170
post #8
post #6

Earlier quoted context omitted.

Wow! They had some great growth going on and it seemed to hit a wall hard around 2008-2009. Any idea why?

http://blog.last.fm/2009/03/24/lastfm-radio-announcement "In all other countries, listening to Last.fm Radio will soon require a subscription of €3.00 per month."

And at the same time they weren't treating us as customers, more like second rate users.
Post reply on HN