Live data from Hacker News

Ken Thompson's Unix Password

leahneukirchen.org

181–190 of 665 posts

Re: Ken Thompson's Unix Password

#181
post #156

Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…

I don't know what to think about this. A password is supposed to be secret so I don't know what a naughty phrase in secret is a violation of? It is not very different from writing something naughty in a private diary, or even thinking a naughty thing.

Not to mention "creepy" is a charge that is often impossible to defend yourself from. It's wholly dependent on the subjectivity of the accuser and their opinion of the accused.

Walk over and say good morning every day to a coworker and she finds you attractive? Charming and sweet. Walk over and say good morning every day to a coworker and she finds you unattractive? Creepy.

Re: Ken Thompson's Unix Password

#182
post #175

Earlier quoted context omitted.

The guy wasn't fired for the password, he was fired for the sexual harassment of a coworker. And nothing you do on a work computer is secret from your employer. It's not a "private diary" if you're using your employer's hardware.

If he was fired for sexual harassment, that is one thing. But a naughty password on its own? That was maybe not the case here but that is what I have doubts about.

And people wonder why tech has a massive issue with sexism...

Re: Ken Thompson's Unix Password

#183
post #58
post #40

i deduced my dad's password when I was a middle-schooler. The uni micro had a teletype and although it did not echo password characters, if you mistyped your password, it would print the mistyped password, and knowing a bit about my dad, I could figure out what the correct password was. I logged in and sent himself an email reminding him to use a better password.

>if you mistyped your password, it would print the mistyped password, That's incredibly useful. Stand next to someone, casually chatting, while they enter their password. Just before they hit [ENTER], stab a key -- say, a 'z'. Boom, it prints their password with an extra 'z' at the end. Sure, they'd be aware of it and likely change their password. But still. A more common use case would be to hang around and wait for…

I've never done anything malicious with the knowledge, but I've totally learned people's passwords just by watching their fingers type. I make an effort to have passwords that would be difficult for a human to nail down while watching them typed quickly in real time. The ubiquity of cameras has me reconsidering input and/or authentication mechanisms, though.

Re: Ken Thompson's Unix Password

#184
post #156

Earlier quoted context omitted.

I don't know what to think about this. A password is supposed to be secret so I don't know what a naughty phrase in secret is a violation of? It is not very different from writing something naughty in a private diary, or even thinking a naughty thing.

The guy wasn't fired for the password, he was fired for the sexual harassment of a coworker. And nothing you do on a work computer is secret from your employer. It's not a "private diary" if you're using your employer's hardware.

>he was fired for the sexual harassment of a coworker

OP is vague on what this guy actually did. Note that they only went to the girl after cracking the password, and she said he was "creepy" towards her.

"Creepy" in this context might just mean FWU (flirting while ugly).

Re: Ken Thompson's Unix Password

#186
post #181
post #156

Earlier quoted context omitted.

I don't know what to think about this. A password is supposed to be secret so I don't know what a naughty phrase in secret is a violation of? It is not very different from writing something naughty in a private diary, or even thinking a naughty thing.

Not to mention "creepy" is a charge that is often impossible to defend yourself from. It's wholly dependent on the subjectivity of the accuser and their opinion of the accused. Walk over and say good morning every day to a coworker and she finds you attractive? Charming and sweet. Walk over and say good morning every day to a coworker and she finds you unattractive? Creepy.

Ugh. Please don't bring this redpill malarkey to hackernews

Re: Ken Thompson's Unix Password

#187
post #45

Earlier quoted context omitted.

The early days of mainframes had some groups of individuals who advocated for no passwords or just your username again as a password: https://www.oreilly.com/openbook/freedom/ch07.html

you're confusing mainframes with UNIX microcomputers, and 1983 wasn't early. Also, I rememebr when FSF hosted UNIX machines at MIT that you could telnet into without a password. It was a total mess.

You're right, my mistake!

Re: Ken Thompson's Unix Password

#188
post #166

Earlier quoted context omitted.

Would you be OK with your use of work bathrooms being made public? You can have an expectation of privacy while using other people's stuff.

If I was writing down offensive stuff about a coworker in the bathroom, that seems fair.

Being offensive is the privacy line?

I prefer the don't trust anything on your work machines or work equipment to be private, especially if it's synced with a server or directly from a server.

If it was his individual laptop or something it might be slightly different but the etc directory was remotely accessible and his password clearly matters to the company's security. Like a rented apartment a heads up beforehand might be a good courtesy not a requirement though.

Re: Ken Thompson's Unix Password

#189
post #166

Earlier quoted context omitted.

Eh, he was typing that phrase at a work keyboard everyday.

Would you be OK with your use of work bathrooms being made public? You can have an expectation of privacy while using other people's stuff.

Are you comparing a work computer to a restroom used by dozens, if not hundreds of people everyday?

Do the sales guys and C-level execs get an expectation of privacy to snort coke in the bathroom?

"Reasonable explanation of privacy" doesn't necessarily apply to "at will" employment.

Every company, large or small has some form of acceptable usage policy for their systems. Anything you type in can and will be used against you if necessary.

Re: Ken Thompson's Unix Password

#190
post #109

Earlier quoted context omitted.

Is it? I mean, I'm not a chess expert, but can we actually call a chess game open or closed from only the first move?

1.d4 d5 is called the Closed Game. It's the name of the opening, just like the Ruy Lopez or the Benko Gambit.

oh, today i learned there are opening moves called the "Open Game" and the "Closed Game" and there are also "open" and "closed" games in chess.
Post reply on HN