Live data from Hacker News

The password “ji32k7au4a83” has been seen over a hundred times

twitter.com

81–90 of 296 posts

Re: The password “ji32k7au4a83” has been seen over a hundred times

#81

Some sites are throwaway (example: they force a sign-up). Don't assume all weak passwords used are not conscious decisions. Entropy is too precious to give up to throwaway sites of uncertain backend security.

The word "password" suffices for a lot of those.

You can find lots of examples of throwaway passwords with associated accounts (and submit your own) at bugmenot.com

Re: The password “ji32k7au4a83” has been seen over a hundred times

#82
I'm a scientist. Information theory always felt curious to me because it adopted terminology and concepts similar to that from statistical mechanics but in practice was always much more difficult due to what could be considered what was "random" vs. what was non-random. After sitting back and thinking about it, what is considered "random" of course is a statement of the probability distribution for the set under consideration. For info theory, that set is some set of strings (say passwords) which is really culturally and historically contigent, while in physics land, the set is microstates that determine macrostates, for which the degeneracy of a macrostate depends on the hamiltonian, full stop. I think mathematically, of course the statements you make are similar (hence why you apply the same prob theory to both) but the systems I study are comparatively easier, while really, the underlying probability distribution for strings is really hard to know in practice because it essentially depends on human history and culture up to that point. For example, in a universe without English, English words (say one-to-oned to a discrete set, so strings of positive integers less than 26 + 10 (including decimal numbers)) would be random. In fact, a universe without that particular Chinese IME, if it was done somewhat differently, then ji32k7au4a83 could be random.

It's just interesting to me, another reminder that physics is just that much more easier than anything else.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#83

Earlier quoted context omitted.

If you're interested in learning Chinese, and want to see the bopomofo/pinyin/literal/parallel translations, please check out Pingtype! I wrote it to help me study. Click Advanced > ㄅㄆㄇㄈ if you want the Zhuyin. https://pingtype.github.io

Was lurking profiles of the Taiwanese crowd on HN. How is it to work as a Software engineer in Kaoshuing?

I left in August last year and am now in New Zealand. I wrote control systems software at a factory making USB, SD, microSD cards - so many good memories. Email me if you'd like to chat about it more!

Re: The password “ji32k7au4a83” has been seen over a hundred times

#84
post #29

Let this thread be a reminder for everyone to use a password manager.

I'm willing to bet that a major upcoming security disaster is a compromised password manager that leaks out tens of millions of accounts and passwords in nicely structured XML that's perfect for automated attacks and frauds. Yes, I use a password manager too, but an ancient one that has no Internet connection, no syncing, and no cloud storage. The only "modern" password manager I've been able to find that works compl…

Well, I use pwgen and gpg ┐(´ー`)┌

A great thing about password managers is that you can change your passwords more often since you don't have to bother coming up with and remembering new passwords. It can even be somewhat automated with pass-rotate: https://github.com/ddevault/pass-rotate

Re: The password “ji32k7au4a83” has been seen over a hundred times

#85
post #49
post #34

This is using the zhuyin keyboard which most likely means Taiwanese users since Taiwan is probably the sole user of the zhuyin keyboard. Typing that out on a zhuyin keyboard gets you: ㄨㄛˇㄉㄜ˙ㄇㄧˋㄇㄚˇ In Pinyin that is wo3 de mi4ma3 Or in English "my password"

For the unfamiliar, "ㄨㄛˇㄉㄜ˙ㄇㄧˋㄇㄚˇ" is an example of "bopomofo" script, the phonetic system used to teach kids reading and pronunciation in Taiwan, and adapted to Chinese keyboard input (zhuyin). I learned it in the 1990s studying Mandarin in Taipei. It maps closely to pinyin romanization used in China (i.e., "ㄨㄛˇ" = "wo3" which is the sound in the Mandarin dialect for "我" and potentially other characters with the sam…

Repulic Of China used to be the government of China duing 1912 to 1949 before moved to Taiwan. It was invented early time of that government. Long time ago in mainland the period was called "before liberation". I had some "before liberation" books with the scripts which was very interesting but seems to be never used in Mainland China after "liberation" as I know.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#87

Earlier quoted context omitted.

Holy shit! Now that I have changed the password, can you please tell me how did you guess that?

Because bunch of us memorized fckgw rhqq2 yxrkt 8tg6w 2b7q8 for the very same reason back in early 2000s

it's even on wikipedia: https://en.wikipedia.org/wiki/Volume_licensing#Leaked_keys

Re: The password “ji32k7au4a83” has been seen over a hundred times

#88
post #29

Let this thread be a reminder for everyone to use a password manager.

I'm willing to bet that a major upcoming security disaster is a compromised password manager that leaks out tens of millions of accounts and passwords in nicely structured XML that's perfect for automated attacks and frauds. Yes, I use a password manager too, but an ancient one that has no Internet connection, no syncing, and no cloud storage. The only "modern" password manager I've been able to find that works compl…

What I do is use a password manager, but when it enters a password into an app or site, I type a few more characters after the end of it before logging in.

Kind of a secondary master password that's not stored anywhere except my memory and my safe.

Best of both worlds in my opinion.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#89

Related story: For some weird reason, I memorized the serial key for a very popular software (I must be fifteen then). Even today, I can recite the 25-letter key without a hitch. And I have used its first ten letters as a password to one of my accounts. Guess what? The password has been used 4000+ times before [1]. It's hard to digest the fact that there are at least a thousand people in the world who did the same th…

Word of warning, if you use an ad/content blocker like uBlock Origin, and block 3rd-party JS, then HIBP may give up on its k-anonymity mechanism and just sends your password to their server in cleartext. Ensure you specifically permit loading jQuery from cloudflare.com, and check network traffic using a test password first.

I'm still impressed by the number of technical people that are willing to give you their passwords by a way or another, a common way being when they are offered to check if his password has been leaked.

Once a friend shared with me one of those services, he got surprised when I raised my concern about compromising his password, he took a second to check the developer tools to see if there was any request including his password, there wasn't, so he called me crazy (it's well known that malicious sites behave differently on certain conditions, one is having the developer tools opened).

Anyway, I suppose that this blind trust is what makes phishing attacks so effective.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#90
post #52

Speaking of good passwords, I wrote a passphrase generator once that I still use to this day. You can have a copy of it if you’d like. The README explains all there is to know about it but feel free to ask any questions anyone might have. https://github.com/ctsrc/Pgen

One of the password generation tools -- so long ago I forget which one, but probably 1Password -- generated a password for me, and I loved the scheme it used. I still use a variety of it but now I make them up myself. The rules: 1. Make up a short nonsense word (so it's pronounceable). 2. Pick 3 numbers. 3. Make up another short nonsense word. 4. Concat them with hyphens, capitalising the first letter. So let's go wi…

An attacker that knows your algorithm can restrict the search space to only sequences that follow the algorithm.
Post reply on HN