Live data from Hacker News

The password “ji32k7au4a83” has been seen over a hundred times

twitter.com

271–280 of 296 posts

Re: The password “ji32k7au4a83” has been seen over a hundred times

#271
post #263

Earlier quoted context omitted.

How are trans people excluded from human rights, again? I seem to have missed that part in my source [0], because that should certainly be covered most formidably by article 3, "Everyone has the right to life, liberty and security of person". [0] http://www.un.org/en/universal-declaration-human-rights/inde...

Rights that aren't asserted are not likely to be respected. Yes, of course these rights apply to everyone, but the laws and policies being enacted aren't taking those rights away from everyone, they're taking them away from trans people. If there were laws passed to do things like prevent cisgender men and women from using anything other than unisex bathrooms, it wouldn't make much sense to rally support for trans ri…

> Rights that aren't asserted are not likely to be respected.

I don't see that happening at all. I find this whole activism trope a dangerous game, they indoctrinate each other with a mindest to disregard empirical data and disrespecting authorities put in place by governments.

> do things like prevent cisgender men and women from using anything other than unisex bathrooms

I'm pretty convinced that where I live you can use whichever bathroom you like, while dressing like the unicorn you are. I'll still be using a urinal, though, because I don't want to make a mess for people, cis or not cis, that need to use the bathroom for more serious business.

> infringement against trans people, specifically

I condemn violence, especially against one-legged single-parent dwarves. They deserve better and you damn well know it.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#272
post #60

Earlier quoted context omitted.

Even if you've provided information which narrows your password down to ~5,000 possible values, you've effectively handed out your password to one of 5,000 internet strangers whom you will never meet in real life. Then consider that this is Hacker News, and how many of those 5,000 have both the skills and motivation to exploit the information you've provided. Never give out "hints" about your password. Not its conten…

Sure, many of us have the skills to exploit that information, but the motivation? This isn't Mos Eisley.

I can already see it. 2 weeks later he will post about having made a fortune with BTC and losing it all.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#273

Earlier quoted context omitted.

Lord of the rings?

I feel like that doesn't meant the description, and I really want to know if I'm missing a famous fantasy series.

Does Discworld count?

Re: The password “ji32k7au4a83” has been seen over a hundred times

#274
post #246

Earlier quoted context omitted.

I feel like that doesn't meant the description, and I really want to know if I'm missing a famous fantasy series.

Like Harry Potter?

First 10 characters, so it would be: harrypotte

Re: The password “ji32k7au4a83” has been seen over a hundred times

#275

Earlier quoted context omitted.

Holy shit! Now that I have changed the password, can you please tell me how did you guess that?

Because bunch of us memorized fckgw rhqq2 yxrkt 8tg6w 2b7q8 for the very same reason back in early 2000s

Ahh, good old F* George W.

Yeah, I had that one committed to memory in highschool.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#276
post #271

Earlier quoted context omitted.

Rights that aren't asserted are not likely to be respected. Yes, of course these rights apply to everyone, but the laws and policies being enacted aren't taking those rights away from everyone, they're taking them away from trans people. If there were laws passed to do things like prevent cisgender men and women from using anything other than unisex bathrooms, it wouldn't make much sense to rally support for trans ri…

> Rights that aren't asserted are not likely to be respected. I don't see that happening at all. I find this whole activism trope a dangerous game, they indoctrinate each other with a mindest to disregard empirical data and disrespecting authorities put in place by governments. > do things like prevent cisgender men and women from using anything other than unisex bathrooms I'm pretty convinced that where I live you c…

you are a bigot in denial. have fun being hateful!

Re: The password “ji32k7au4a83” has been seen over a hundred times

#277
post #167

Earlier quoted context omitted.

While you're correct mathematically, I still think it's a good habit to give zero information about your password. If you attempt to estimate the information leakage with every "hint", sooner or later you'll slip up.

My view is your secrets should be secure even if the attacker knows everything about how they are generated and used. For example: My password is 8192 characters long, leveraging only the ASCII character set (except \n\r\t\0) It is changed every 28days at 11:05am It is only used on exactly 1 website and the username on that website is also only used on that website and randomly generated as well. Good luck (Tell me h…

> Tell me how and where I can make this stronger

Make it 8193 characters long, change it every 27 days at 11:04am, but most importantly: use it on exactly 0 websites.

Good luck

Re: The password “ji32k7au4a83” has been seen over a hundred times

#278

Earlier quoted context omitted.

Gotcha. I guess I was unclear about what "almost as secure" meant in this context. So whether providing your length is a tangible security leak or not is essentially a function of the size of your character pool, because if your password is short enough for n-1 to contain a significant percentage of possible combinations then it's probably already short enough to brute force anyway.

That's not right. You can make a secure password using only ABC as your character pool, if you make it 60 characters long. In that case the percentage of combinations covered by n-1 is a full third of the n character combinations, and your attacker can get a 25% speed boost by you revealing the length. But it's still more secure than a 59 character password, and far more secure than a 57 character password, and all o…

A 25% speed boost is what I would call a significant percentage. Especially at 60 characters. My statement holds up.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#279

Earlier quoted context omitted.

That's not right. You can make a secure password using only ABC as your character pool, if you make it 60 characters long. In that case the percentage of combinations covered by n-1 is a full third of the n character combinations, and your attacker can get a 25% speed boost by you revealing the length. But it's still more secure than a 59 character password, and far more secure than a 57 character password, and all o…

A 25% speed boost is what I would call a significant percentage. Especially at 60 characters. My statement holds up.

What you're missing is that a 59 character password (with secret length) is extremely secure, despite the even larger speed boost.

If you worry about any speedup in password cracking that is less than an order of magnitude, your password was too close to failing to start with. Make your password 5% longer, which will make it at least 20x slower to crack, and then you won't have to care if "20x" gets reduced to "15x".

You may say "It's not harmless to give up 25%. What if I give up 25% several times? That could make even a good password become insecure." but there's a limit to how much speedup someone can get from knowing the structure of your password. And the best way to evaluate the strength of a password is to assume that all the structure is public. So I can say that my typical passwords, being 20 mixed-case letters and numbers, all have a security of 2^119. It's possible that an attacker that uses the wrong algorithm would have to guess even more, but I'm not just worried about a clumsy attacker, I'm also worried about a moderately-high-quality attacker. It's a bad idea to depend on that extra .1 bit I could get with this character set, or that extra .4 bits I could get with a smaller character set. Just assume the length is known.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#280
post #276
post #271

Earlier quoted context omitted.

> Rights that aren't asserted are not likely to be respected. I don't see that happening at all. I find this whole activism trope a dangerous game, they indoctrinate each other with a mindest to disregard empirical data and disrespecting authorities put in place by governments. > do things like prevent cisgender men and women from using anything other than unisex bathrooms I'm pretty convinced that where I live you c…

you are a bigot in denial. have fun being hateful!

[deleted]
Post reply on HN