Live data from Hacker News

86% of CrashCrate subscribers used passwords already leaked in other breaches

troyhunt.com

71–80 of 145 posts

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#71
post #15

86% of my passwords are for low consequence sites. How much should I care if someone hacks my handle and posts ads on a chat site? Or reads registration-required articles under my registration? Or etc etc.

'Security' is some kind of religion in tech circles. I don't know if it is just that risk analysis isn't part of your standard tech education, or if they think it makes them look cool to talk about always using 200 character hardware-RNG generated passphrases when ordering pizza online, or what exactly, but they're everywhere.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#72

At bare minimum websites should use 2FA - a simple TOTP on any smartphone will do wonders. But, the issue is that 86% of all websites offer so little value that 86% of people would just not bother using the site if they had to do the 2FA dance each time. That is the fundamental problem here - not people reusing passwords, or password policies that break when encountering my password manager. It's not surprising peopl…

Out of curiosity, I just looked at the list of sites in my password manager, and at least 3/4 of them are sites that I shouldn't even need an account to use! Mostly online shopping sites the wouldn't let me checkout without an account and forums that wouldn't let me do some function without an account. If all online shops were required to let me buy something without creating an account, my "password footprint" would…

I have 118 entries (which seems scary) and a quick scan shows me about 95% are not rubbish (I guess there is a selection process) and something like 2/3rds I have some kind of financial relationship (HMRC/VAT, paypal, phone provider) as well as a (small) number of stores (I think Jeff Bezos needs to be thanked for that)

Overall I am surprised - I would be prepared to use 2FA for quite a lot of those (many I do).

And if those sites mostly moved over to using OAuth with Google or a more privacy minded provider, yeah I would be fairly happy.

In fact why does Apple not do OAuth2? They have the privacy-is-our-thing going for them (as opposed to Google / Facebook whose business model is selling my data).

After that I guess its the UK government Gov.Verify for commercial users

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#73
post #19

Earlier quoted context omitted.

People should use password managers, but it's a crutch.

If it is well integrated with your browser it's quite ok. Maybe not as convenient as using the same simple password everywhere but certainly a lot better than having to remember a lot of different passwords ;)

I personally prefer _not_ integrating my password manager with my browser, even though the option is available. Instead my password manager performs manually-activated autotyping which, while less convenient, does at least 'feel' like it's more secure.

I trust my OS to isolate applications from eachother more than I trust my browser to isolate extensions from the page they run on. LastPass in particular have had their browser extension exploited[0].

[0]: https://blog.lastpass.com/2017/03/security-update-for-the-la...

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#74
post #48

Earlier quoted context omitted.

If you ever reuse that password anywhere else, then you should care A LOT. If you go "i only reuse passwords on low-consequence sites", then I have to ask you 1) why reuse at all? and 2) are you sure? I bet that that's not true, I bet you think that's true but it turns out that your Uber password is the same as your RandomSite password. Just use a password manager. It's easier and it's safer, and you never have to th…

Unfortunately, OSs don't make it easy to use password managers, especially in mobile. A lot of my banking sites also defeat my password manager with bizarre UX like user name masking and multi step login screens.

Or by disabling automated entry, or with disabling the password field until the username field is filled.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#75

My preference is for long passwords that comprise a natural language sentence. They are easy to remember and hard to brute force once they are greater than 40 characters. You don't need any of these draconian password rules if the password is long enough.

before I got into a password manager, I resorted to song lyrics, capitalizing the first character, including a number and a symbol at the start.

'#1I'm picking up good vibrations', for instance.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#76
post #34

Stop giving your users passwords to Troy Hunt! Eg. hash and salt them! But use a really slow hash . Lets say the hashing speed is one hash per second, then it would take trillion years to brute force the password "hello".

You have that backwards. You don't bruteforce a single password. You compute the hashes of all the dictionary words and then compare the hashes. So your 'trillion years' is probably more along the lines of a few weeks, for all the words in the dictionary at once.

Sure, and that's why salted hashes are a thing.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#77
This riles me up so I will rant.

I've given up remembering passwords for important accounts and just use the 'forgot me password' button to auth through email.

If your site or service doesn't have more than 100 million users, please don't require a password for my email. Let me log in with another trusted account (Google, Twitter, etc). I miss the days of oauth2 and the flexibility of authenticating small services.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#78

My preference is for long passwords that comprise a natural language sentence. They are easy to remember and hard to brute force once they are greater than 40 characters. You don't need any of these draconian password rules if the password is long enough.

before I got into a password manager, I resorted to song lyrics, capitalizing the first character, including a number and a symbol at the start. '#1I'm picking up good vibrations', for instance.

A tad off topic, which password manager would you recommend?

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#79

This riles me up so I will rant. I've given up remembering passwords for important accounts and just use the 'forgot me password' button to auth through email. If your site or service doesn't have more than 100 million users, please don't require a password for my email. Let me log in with another trusted account (Google, Twitter, etc). I miss the days of oauth2 and the flexibility of authenticating small services.

No thanks, it’s far better to handle your own user authentication and not depend on third parties.

Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches

#80

When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…

Just recently Estonian Information System Authority published a new report (including new guidelines for passwords) basically telling: "Drop password requirements, allow long passwords and restrict the use of short and top-n passwords".

Why I'm mentioning this is because now I have an actual official document I can send to Estonian companies in addition to my own words (that weren't previously believed, ugh) why their requirements are inane. I think this kind of behaviour shows that we actually need some kind of monitoring or regulation here to build more secure software for everyone.

Also as you mentioned bad-"strong" passwords, I "love" how something like "Qwerty!1234" satisfies most requirements but "8f434346648f6b96df89dda901c5176b10a6d83961dd3c1ac88b59b2dc327aa4" is not okay because it doesn't contain an uppercase letter or a symbol.

Post reply on HN