Earlier quoted context omitted.
Maybe crypto people who have brute-forced up some typeable passwords that hash to low numbers on the first SHA-1 pass, for a fun-and-games equivalent to a Proof of Work? (It'd only show up in actual DB dumps for backends that use "SHA-1 with no salting" for password hashing, which might also serve as a useful canary value.)
Great idea! I ran a quick hashcat against the range00000 list on my laptop. In 1 minute I cracked 79 of them, and not too many of them look very odd - that is, they look sorta like normal cracked passwords. I'm asking my friend to run a more thorough crack on his dedicated GPU, especially for hash value 000DD7F2A1C68A35673713783CA390C9E93:630 which does stick out to me!
"Pwned Passwords" V2 With Half a Billion Passwords
321–330 of 369 posts
Re: "Pwned Passwords" V2 With Half a Billion Passwords
#322Earlier quoted context omitted.
I would argue that the benefit of putting all the hashes into a separate table is not really worth it. A separate service just to verify passwords sounds an awful lot like reinventing LDAP or AD/Kerberos with less features. It should be good enough to simply encrypt the password hashes with an application-side key, a simple database dump won't leak passwords anymore. If your passwords are properly hashed and stretche…
The point is not putting them in a system that can leak them right alongside the login identifier. If someone wants to go exercise 9384828388 GPUs on your list. Fantastic, at least the other piece of their auth username/etc isn’t sitting right next to it. Putting them in a separate system can be a simple REST server that sits in front of another database, LDAP or even something like Vault. Don’t set them right alongs…
I don't see the benefit of a seperate system still, if you really want to, LDAP already does all this. As does AD. Why reinvent the wheel and built a rest service for it?
I also don't know why it's harmful if a hash sits next to the username, if the database has been breached, password hashes are probably the least valuable information in such a leak. Mail addresses are more valuable.
Re: "Pwned Passwords" V2 With Half a Billion Passwords
#323Earlier quoted context omitted.
Algorithmic password in your head, with a google spreadsheet to keep track of usernames, password rules, etc. on a per site basis (i.e. "bankofamerica, ythn.smith@gmail.com, 4-12 characters - no special). Edit: downvote away, but so far no one has ever been able to give a compelling reason why algorithmic passwords are bad. It has tradeoffs, sure, but so do password managers.
If a couple of your algorithmic passwords get leaked, attached to same email, then the algo could be guessed and you potentially lost all your accounts.
Compare to PW managers: "If your password db and master password get leaked, attached to the same email, then you lost all your accounts." Also with PW manager, losing your phone can mean Denial-of-Service to all of your accounts if you are i.e. travelling.
Re: "Pwned Passwords" V2 With Half a Billion Passwords
#324Earlier quoted context omitted.
If a couple of your algorithmic passwords get leaked, attached to same email, then the algo could be guessed and you potentially lost all your accounts.
That's a lot of unlikely ifs. And that also assumes my algo is easy to reverse from 2 digests. My counter to that is that it is unlikely anyone would specifically target me and waste resources trying to crack my algorithm when there is so much low hanging fruit elsewhere. If I am specifically being targeted, I've probably already lost, even if I use a PW manager. Compare to PW managers: "If your password db and maste…
Don't password managers have 2FA, and alternate phone numbers?
Re: "Pwned Passwords" V2 With Half a Billion Passwords
#325Earlier quoted context omitted.
I've just switched from 1password to keepassxc in the past few weeks. The only reason I did so was because 1password was trying to force me into their subscription service as I switched from macOS to linux mint. I looked at a few work-arounds on github, but eventually just decided to move over to keepassXC. The export / import and overall setup was pretty painless. I am still able to sync through dropbox just like wi…
Just out of curiosity, aren’t you worried that keepasstouch app on the iOS may be compromised?
Although I have not seen any reports of keepasstouch being compromised, it is true that it is not open source ... I had meant to download minikeepass, which is. I've remedied the problem. 2FA keeps me pretty safe on most of my important accounts, but I have still changed pw's on many accounts thanks to your comment. Much appreciated!
Re: "Pwned Passwords" V2 With Half a Billion Passwords
#326Bit off topic, but I was searching for a better way to manage passwords a few weeks ago (rather than have 1 or 2 master passwords across all websites). I found KeePass through an old ask HN thread. It's a great little free, open source key/password storage app that works across all my devices (iOS, macOS, windows). https://keepass.info/ I'd be interested to hear any suggestions for similar apps I could recommend to m…
I was looking at Dashlane which seemed to have some good features, including some ability to do password rotation automatically, and some level of yubikey support. That said I'm still using keepass. I discovered it when I needed a solution that worked on an original Surface RT, as well as an iphone, and I've remained happy.
Thanks for your message. I am Thibault, from Dahslane's User Support team, and am here to provide you with a bit of information.
Here are a few things to know about Dashlane!
* Dashlane does integrate with Yubikeys for Two-factor Authentication. All keys are compatible except for "FIDO U2F Special SECURITY KEY". Please see this link http://bit.ly/2FnNxka for more information on the subject
* Dashlane has been consistently rated the easiest password manager to use, which is extremely important since the last thing you want is a headache every time you’re trying to store or access your passwords. Don’t just take our word for it - Dashlane has over 50,000 5-star reviews.
* Dashlane is the only password manager with a U.S. patent for its security architecture. And your Master Password is never stored on our servers. Never!
* Dashlane’s auto-fill technology, which reads the fields on the page to store or enter data on your behalf, is the most accurate auto-fill in the industry. We’ve benchmarked our auto-fill tech against the competition and have found Dashlane is up to 40% more accurate than other password managers.
* Dashlane invented Password Changer and is the only Password Manager that allows you to change up to 500 passwords in seconds without ever leaving the Dashlane app.
* Dashlane’s VIP customer support is the best in the industry. Super-quick response times, availability via live chat, and premium support keep our customers happy.
You can check out our great review in the New York Times by following this link : http://nyti.ms/2CCUGKr. You will also find Dashlane in first position of PCMag's list of Best Password Managers for 2017 here : http://bit.ly/2BIdv1S.
Please note that although we propose the Password Changer feature, the automatic rotation is yet to be developed. I will pass you request down to the Development team for further consideration.
I confirm you Dashlane is indeed compatible with iOS devices, and you can access your Dashlane account trough the Web App with your Surface RT!
If I can be of any further help, please let me know!
Kind regards,
Thibault Dashlane Customer Support
Re: "Pwned Passwords" V2 With Half a Billion Passwords
#327Earlier quoted context omitted.
I love Dashlane, and the Linux support is solid through the browser extension. Dashlane has the best interface across devices, of all the password managers I've used. The password sharing feature is great for business. Sure, it's a cloud service, but it's polished enough that I can get non-tech people like my family and coworkers to actually use it. Lastpass did not pass that test. I use Dashlane every day on Mac, Li…
Thanks. One question I have - can you turn off auto-login globally or just on a per website basis? Docs seem to imply on a per site basis only but that seems a bit odd. I'm wondering how DashLane handles multiple logins for the same service (Google/GitHub etc etc).
If you mean having several accounts for the same service (aka. Google/Github), then yes. All you will need to do is create a Dashlane "credential" (id+password) per account.
If you mean Federated sign-ins (such as this one https://i.imgur.com/se5toyn.png), then it should be possible as long as the button opens a browser window on the right domain (Facebook, Google, etc).
Please don't hesitate to contact us directly through our Help Center if you have other questions about Dashlane !
https://support.dashlane.com/hc/en-us/requests/new
Kind regards,
Thibault Dashlane Customer Support
Re: "Pwned Passwords" V2 With Half a Billion Passwords
#328Earlier quoted context omitted.
6618 people love life, 1367 want to die. 893 people like turtles, 170 love turtles, 155 love everyone (363 people hate everyone though and 428 hate us all). 4301 people love their dog, 3 fuck their dog, 3 killed their dog (only one person killed their cat) 110 people are killers, 4 kill for money, 1 is a murderer. 68 want to kill, 24 kill for fun :-/ 2781 love their wife, 552 love their husband. 68 people hate their…
> 1 person is the president Don't tell me he actually made that his password...
Re: "Pwned Passwords" V2 With Half a Billion Passwords
#329I think it would be interesting to do an art project with this data - some of these passwords are funny and/or revealing. Some examples: pooplasagna - 3 times eggsarebad - 3 times eggsaregood - 25 times myhusbandcheats - 4 times icheatonmywife - 1 time ihatemyneighbors - 2 times iamanalcoholic - 6 times 1yearsober - 31 times imissmykids - 51 times imissmyparents - 6 times
Re: "Pwned Passwords" V2 With Half a Billion Passwords
#330Earlier quoted context omitted.
That's a lot of unlikely ifs. And that also assumes my algo is easy to reverse from 2 digests. My counter to that is that it is unlikely anyone would specifically target me and waste resources trying to crack my algorithm when there is so much low hanging fruit elsewhere. If I am specifically being targeted, I've probably already lost, even if I use a PW manager. Compare to PW managers: "If your password db and maste…
Other methods being poorer doesn't make your method objectively better. You're probably right on low-hanging fruit, all depends on your threat model I suppose. Don't password managers have 2FA, and alternate phone numbers?