Live data from Hacker News

86% of CrashCrate subscribers used passwords already leaked in other breaches

troyhunt.com

61–70 of 145 posts

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#61
post #34

Stop giving your users passwords to Troy Hunt! Eg. hash and salt them! But use a really slow hash . Lets say the hashing speed is one hash per second, then it would take trillion years to brute force the password "hello".

I don't think you understand how he gets ahold of these passwords. They're from dumps of leaked databases.

I think parent's comment is telling people to store passwords in such a way that they won't be very useful if they are leaked.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#62

At bare minimum websites should use 2FA - a simple TOTP on any smartphone will do wonders. But, the issue is that 86% of all websites offer so little value that 86% of people would just not bother using the site if they had to do the 2FA dance each time. That is the fundamental problem here - not people reusing passwords, or password policies that break when encountering my password manager. It's not surprising peopl…

Please not. I don't want to use a 2FA for every crappy website with a login, nor do I have my phone with me all the time. (optional is fine of course)

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#63

When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…

I completely agree. "Your password must be at least 10 character long, include 2 upper case, 2 lower case, 2 digits, 2 special characters, must be changed every 60 days and cannot be reused for the next 3 years"

G0Fuc4Y@urse!f

To me this is a sure way that people are gonna pick horrible and stupid passwords.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#64

Earlier quoted context omitted.

1. With a password manager, you don't have to think anymore if a site is high-consequence or low-consequence. 2. What kinds of websites that require a sign-in are actually low-consequence? I can't think of any from the top of my head, but that's probably because I'm pretty reluctant to sign up to new sites.

To be honest, the first one that comes to mind is HN. There is zero consequence if someone was to get a hold of my credentials here — I don't care about the score and I can still recover the bookmarks.

What if the person that takes over the account posts messages that arouse the interest of authorities? Your IP addresses and other info are associated with the account.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#65
post #48
post #15

86% of my passwords are for low consequence sites. How much should I care if someone hacks my handle and posts ads on a chat site? Or reads registration-required articles under my registration? Or etc etc.

If you ever reuse that password anywhere else, then you should care A LOT. If you go "i only reuse passwords on low-consequence sites", then I have to ask you 1) why reuse at all? and 2) are you sure? I bet that that's not true, I bet you think that's true but it turns out that your Uber password is the same as your RandomSite password. Just use a password manager. It's easier and it's safer, and you never have to th…

Unfortunately, OSs don't make it easy to use password managers, especially in mobile. A lot of my banking sites also defeat my password manager with bizarre UX like user name masking and multi step login screens.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#67
My preference is for long passwords that comprise a natural language sentence. They are easy to remember and hard to brute force once they are greater than 40 characters. You don't need any of these draconian password rules if the password is long enough.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#68
The depressing thing is that every new company I join has terrible password hygiene: shared accounts (even on services that don't force it), passwords reused on multiple services, terrible passwords, passwords emailed around, passwords in word docs that are emailed around ...

If IT people can't get this right, it's impossible for the average person to EVER get this right. We need a better solution.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#69
post #48

Earlier quoted context omitted.

If you ever reuse that password anywhere else, then you should care A LOT. If you go "i only reuse passwords on low-consequence sites", then I have to ask you 1) why reuse at all? and 2) are you sure? I bet that that's not true, I bet you think that's true but it turns out that your Uber password is the same as your RandomSite password. Just use a password manager. It's easier and it's safer, and you never have to th…

Unfortunately, OSs don't make it easy to use password managers, especially in mobile. A lot of my banking sites also defeat my password manager with bizarre UX like user name masking and multi step login screens.

I use keypassx on Mac, Windows, and Android. It is a minor pain to have to log into it to grab my username and password, but worth it. I sync the encrypted DB with Dropbox.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#70
post #64

Earlier quoted context omitted.

To be honest, the first one that comes to mind is HN. There is zero consequence if someone was to get a hold of my credentials here — I don't care about the score and I can still recover the bookmarks.

What if the person that takes over the account posts messages that arouse the interest of authorities? Your IP addresses and other info are associated with the account.

Are you posting on Hacker News from your own IP address?!?! :-O
Post reply on HN