Earlier quoted context omitted.
You seem obsessed with one implementation. Passwords themselves are obsolete. Actually the problem is already solved for at least a decade: Certificate based authentication. Browsers support it. Try StartSSl registration, for example.
Client certificates tie the user to a specific device, which is terrible. It just moves the problem back to "account recovery".
43M passwords hacked in Last.fm breach
161–170 of 172 posts
Re: 43M passwords hacked in Last.fm breach
#162Earlier quoted context omitted.
With the Dropbox hack for example, the reason they got hacked is because one of their employees reused a password, presumably from another site that got hacked. So that's one vector, where every time a site gets hacked, people using weak passwords (and reusing them) create the risk of future hacks. But more generally, exposing your account credentials allows others to impersonate you and potentially scam others, expo…
Should people be fined for not locking their doors?
Re: 43M passwords hacked in Last.fm breach
#163We really need some laws around this... Prison time for web developers that store passwords insecurely, and substantial fines for anyone whose password can be brute forced from one of these leaks.
Re: 43M passwords hacked in Last.fm breach
#164Earlier quoted context omitted.
Do you have any domain name (even if it has no webserver yet) or some pre-launch page to bookmark? Don't need such service now, but I had accidental necessity in past few years. (Also, please consider submitting it to HN when you go live.)
I bought the domain name smsprivacy.org but I could plausibly end up on a different one. I will submit a Show HN. Thanks :)
Re: 43M passwords hacked in Last.fm breach
#165Re: 43M passwords hacked in Last.fm breach
#166> The number of passwords and the severity of the hack was not uncovered until today. The passwords were stored using unsalted MD5 hashing Enough said. > The most popular password pulled from the Last.fm database was 123456. Seriously, it’s 2016 people Sure, but the breach was in 2012 TechCrunch. Better article: http://www.leakedsource.com/blog/lastfm
> Sure, but the breach was in 2012 Even in 2012, storing passwords unsalted (and probably even hashed just once) was considered bad practice. As was MD5. Bad passwords being bad passwords also goes without saying. 123456 was never a good password.
Re: 43M passwords hacked in Last.fm breach
#167Re: 43M passwords hacked in Last.fm breach
#168Regular reminder that new users in general don't care at all about the security of your site. Most of your signups are not going to generate and store a secure password "just to try you out", as evidenced by the most common password here "123456". If you force people to signup to try your site/app, many (most?) of them are going to use a crap password. If you're _lucky_ that'll be 123456, and not their email/facebook…
OpenID registration is the solution to this problem.
Re: 43M passwords hacked in Last.fm breach
#169Earlier quoted context omitted.
Wow! They had some great growth going on and it seemed to hit a wall hard around 2008-2009. Any idea why?
Easy. CBS bought them late 2007. Dev and updates pretty much stopped. They limited tracks you could play directly. Then they killed radio. I'm really sad to see it die, it was better at introducing me to new artists than any other service before or since, and the radio was brilliant.
Re: 43M passwords hacked in Last.fm breach
#170Earlier quoted context omitted.
Wow! They had some great growth going on and it seemed to hit a wall hard around 2008-2009. Any idea why?
http://blog.last.fm/2009/03/24/lastfm-radio-announcement "In all other countries, listening to Last.fm Radio will soon require a subscription of €3.00 per month."