Live data from Hacker News

At Blind, a security lapse revealed private complaints from tech employees

techcrunch.com

81–90 of 141 posts

Re: At Blind, a security lapse revealed private complaints from tech employees

#81
post #67

This bothers me: > The database also contained passwords, which were stored as an MD5 hash, a long-outdated algorithm that is nowadays easy to crack. Many of the passwords were easily unscrambled using readily available tools when we tried. That's not how hash functions work... > Kim denied this. “We don’t use MD5 for our passwords to store them,” he said. “The MD5 keys were a log and it does not represent how we are…

Ummm, that is exactly how password cracking works.

The fact the reporter actually went the extra step to crack some of the hashes is impressive reporting actually.

Re: At Blind, a security lapse revealed private complaints from tech employees

#82

I'd never checked out Blind before. I just went there and checked out a few of the front page posts & comments. It has some of the most toxic and destructive "advice" I've seen for people asking for help or insight. I'm a bit astounded. Is this typical?

It's pathetic, you see some of the most depraved, narcissistic members of the tech society there. The quality of the discourse you can guess is shockingly bad, and most people are from the Bay area. Is this an accurate representation of people in the Bay? Or is it just a platform for toxic folk to hang out?

I think that because it's basically unmoderated you either get: 1. Posts that are usually removed elsewhere stay 2. People who would otherwise go elsewhere (because their posts are removed) stay. But it is incredibly problematic.

Re: At Blind, a security lapse revealed private complaints from tech employees

#83

I'd never checked out Blind before. I just went there and checked out a few of the front page posts & comments. It has some of the most toxic and destructive "advice" I've seen for people asking for help or insight. I'm a bit astounded. Is this typical?

It's pathetic, you see some of the most depraved, narcissistic members of the tech society there. The quality of the discourse you can guess is shockingly bad, and most people are from the Bay area. Is this an accurate representation of people in the Bay? Or is it just a platform for toxic folk to hang out?

I hope it's just where the toxic find their voice, an echo chamber for a hopefully small minority of the total population. It's really depressing to think that so many well-educated people are so narrow minded and lacking in empathy. It would however explain the systemic irresponsible behavior present in some companies such as Facebook and Uber. It's easy to believe that even a minority of such people could be the bad apples that spoil the rest.

Re: At Blind, a security lapse revealed private complaints from tech employees

#84
post #71
post #69

Earlier quoted context omitted.

The passwords were md5 hashed and most likely broken using dictionary attack or brute forced with tools like hashcat. I forgot my password once, but I knew the general letters and it brute forced in a minute.

Yeah weak hashes are easy to replicate, I was just laughing at the words they used.... Unscramble, like it's an encryption method or something.

It sounded more like you were trying to discredit the report. The terms are well accepted laymen terms to use when talking about cracking passwords.

Re: At Blind, a security lapse revealed private complaints from tech employees

#85

> Blind claims on its website that its email verification “is safe, as our patented infrastructure is set up so that all user account and activity information is completely disconnected from the email verification process.” Wow a patented infrastructure! Dope! I wonder if it's open source so that can be validated objectively?

I guess you can at least look up the patent and validate the idea.

Re: At Blind, a security lapse revealed private complaints from tech employees

#86
post #69
post #67

This bothers me: > The database also contained passwords, which were stored as an MD5 hash, a long-outdated algorithm that is nowadays easy to crack. Many of the passwords were easily unscrambled using readily available tools when we tried. That's not how hash functions work... > Kim denied this. “We don’t use MD5 for our passwords to store them,” he said. “The MD5 keys were a log and it does not represent how we are…

The passwords were md5 hashed and most likely broken using dictionary attack or brute forced with tools like hashcat. I forgot my password once, but I knew the general letters and it brute forced in a minute.

[deleted]

Re: At Blind, a security lapse revealed private complaints from tech employees

#88

Earlier quoted context omitted.

It's pathetic, you see some of the most depraved, narcissistic members of the tech society there. The quality of the discourse you can guess is shockingly bad, and most people are from the Bay area. Is this an accurate representation of people in the Bay? Or is it just a platform for toxic folk to hang out?

I hope it's just where the toxic find their voice, an echo chamber for a hopefully small minority of the total population. It's really depressing to think that so many well-educated people are so narrow minded and lacking in empathy. It would however explain the systemic irresponsible behavior present in some companies such as Facebook and Uber. It's easy to believe that even a minority of such people could be the ba…

>It's really depressing

It's also very useful, if accurate.

Re: At Blind, a security lapse revealed private complaints from tech employees

#89
post #14

>At its core, the app and anonymous social network allows users to sign up using their corporate email address, which is said to be linked only to Blind’s member ID. People just trusted it? I get that to seem legitimate the users have to be confirmed in some way, but as a user... now way am I exposing myself that way.

I would go further and say using it is gross incompetence along the lines of a broker taking stock investment advice from spam email. Literally the only reason why someone would send out random stock advice like that is doing a pump and dump scheme. Similarly if they aren't going to use your email then they have no reason to ask for it and any 'anonymous' app that asks for identifying information isn't.

I get the sentiment you are sharing and I am not advocating execution of Blind anyway, but it you want to make anonymous "rooms" like say peole from Google belong to one room and Facebook to another. How'd you make that without first establishing that someone is from Google.

I understand taking their work email is asking for more info than desired. Probably they can use something zero-knowledge (I am not well aware of the concept) where someone proves their employer's identity without their own.

Re: At Blind, a security lapse revealed private complaints from tech employees

#90

"Uber — which later blocked the app on its corporate network." Reason enough not to work there if you ask me.

I don't think this claim is true. Friends who work there clarified they can use Blind at the corp network.
Post reply on HN