I don’t understand why the author thought it would take years to find this password, as opposed to something closer to the four days it actually took.
Ken Thompson's Unix Password
161–170 of 665 posts
Re: Ken Thompson's Unix Password
#162Re: Ken Thompson's Unix Password
#163Re: Ken Thompson's Unix Password
#164Re: Ken Thompson's Unix Password
#165Re: Ken Thompson's Unix Password
#166Earlier quoted context omitted.
Even if the guy was creepy, you are an asshole revealing something he thought nobody could ever know. That's the same thing like reading his personal letters or similar.
Eh, he was typing that phrase at a work keyboard everyday.
Re: Ken Thompson's Unix Password
#167Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…
I don't know what to think about this. A password is supposed to be secret so I don't know what a naughty phrase in secret is a violation of? It is not very different from writing something naughty in a private diary, or even thinking a naughty thing.
And nothing you do on a work computer is secret from your employer. It's not a "private diary" if you're using your employer's hardware.
Re: Ken Thompson's Unix Password
#168Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…
I'm all for the effective strength enforcement and ejecting the creepy guy, but some people do have strong passwords that, a bad idea though it may be, embed something deeply personal to them. Just something to keep in mind before automating the sharing of cracked passwords for otherwise legitimate purposes. I consider my passwords my private information, even if they are no longer secure from a technical standpoint…
It's very legitimate for a company to want to protect themselves from a massively damaging and costly security/privacy incident by policing against the use of weak passwords.
Re: Ken Thompson's Unix Password
#169Re: Ken Thompson's Unix Password
#170I'm shocked at how well the old hashing stood up; sure, it's totally crackable today, but a well-picked password still took 4+ days to crack on modern hardware, which is remarkable. (Granted, it doesn't sound like they did anything fancy like throwing a hundred cloud instances at it or something; I'm not saying you should use DES today:) )
30 years ago I cracked everyone’s Unix password on an old Sun computer. It didn’t take long because everyone had a password that was in the dictionary. Needless to say, people were not happy with the messenger.