Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…
I'm conflicted about this. I know I'd be pretty upset if an employer starting talking to me about a plaintext password that's supposed to be hashed. The problem is that they brute forced it and then sent it directly off to HR? Yes, as a sysadmin it's perfectly acceptable to be searching for weak passwords, but reading the plaintext yourself for fun then scurrying to HR is kinda a slimy thing to do. As an admin you ha…
Ken Thompson's Unix Password
221–230 of 665 posts
Re: Ken Thompson's Unix Password
#222Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…
Re: Ken Thompson's Unix Password
#223Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…
A proper policy would’ve been to not have any human look at a user’s password and just email them a warning about their weak password. A password should be considered a PPI (personal, private information) and off limits to others, no matter how creepy (exception being a legal warrant). These days you might gotten in trouble!
Although I don't think it's PII if it's all internal company data, especially if it is known that IT will crack your password.
Re: Ken Thompson's Unix Password
#224Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…
I don't know what to think about this. A password is supposed to be secret so I don't know what a naughty phrase in secret is a violation of? It is not very different from writing something naughty in a private diary, or even thinking a naughty thing.
I don't know if I'm too normal or what, but my gut feeling is that yes it's really creepy. And all these things have different creepiness to them. Thinking a naughty thing is the least creepy. A private naughty diary is starting to be creepy. If it's just a passage in a normal diary, it's not too bad, if there's a whole book just about this one girl it would get super creepy. Making your work password a naughty phrase about the girl working in front of you, definitely super creepy.
Some of those I'd start to consider beginning signs of harassment honestly. The password one, it's like slowly trying to bring to the girls attention your thoughts. What's happening, are you hoping they see you typing it out one day? Everytime you type it do you stare at her and imagine whatever you typed? So ya, if there was all kinds of other similarly creepy small behaviors they'd add up to a pretty bad environment for that girl to be working in.
Just my opinion. Maybe I'm overreacting, but I wouldn't do that, and so I find it very surprising and creepy that someone else does. Are they harmless, innocent, didn't know better, just have a cute crush, nice guys, maybe, but doing something unexpected to me, that I'd never think of doing, is pretty much the defining characteristic of creepy, and it naturally puts me on my guard. It's just strange behavior, and that's scary.
Note: I'd like to hear some replies that are like... oh no, it's not creepy, way more people have naughty passwords or big naughty diaries of their coworkers than you think. I know I do. It's a totally normal behavior, you're the actual outlier here if you never did any of that. Otherwise I will continue to believe this is strange and creepy behavior which warrants suspicion, and possibly a good indicator that someone makes others feel uneasy and unsafe when around them.
Re: Ken Thompson's Unix Password
#225Earlier quoted context omitted.
>he was fired for the sexual harassment of a coworker OP is vague on what this guy actually did. Note that they only went to the girl after cracking the password, and she said he was "creepy" towards her. "Creepy" in this context might just mean FWU (flirting while ugly).
I think it's very interesting how, despite knowing nearly nothing about the situation, everyone here is quick to doubt the victim, and make up scenarios (for which there is zero evidence) where the harasser is the victim.
Some people evidently want that, because they're "not a witch" themselves.
It's really awful that in some/many cases, accusations of rape or sexual assault or sexual harassment or creepiness end up reducing to one person's word against another, when there's no good objective evidence either way.
You should doubt everyone. You should doubt the accuser. You should doubt the alleged harasser's claim of innocence. Without evidence, you can't adjudicate it, and unless it's a matter of rape or sexual assault, the compulsion to adjudicate it in the absence of evidence is unhealthy[1]. What you can do is try to engineer the environment or counsel the people so the alleged behavior by the accused or negative perception by the accuser is less likely to occur; most obviously, by separating them and ensuring they rarely/never have to interact.
If you can't keep the two people from communicating or interacting, and you have to fire one, and that one should be the accused, that is precisely a witch trial, but without a declaration of being a witch. The accused might not be a witch, but we're going to burn them anyway, because the social fabric depends on it!
And of course, criticizing witch trials can make you a witch, because there's evil in the world and therefore the witch trials must go forward! To do nothing is to enable witches, and who would want to do that except a witch? "Cui bono?"
[1] And in serious cases, you can try to take it to court, but it'll fairly likely end up unsatisfactorily for the accuser unless they're particularly persuasive or the defendant is obviously creepy or there's some other evidence. Even a string of accusers, although it means something, is not necessarily good evidence. Again, see the witch trials.
Re: Ken Thompson's Unix Password
#226I had a password for an old school system (which I wrote) that was "any 21 characters where the 21st character is a 'z'". People would watch me type it (mashing 20 keys then the 'z') and be amazed I could remember a password that long.
Re: Ken Thompson's Unix Password
#227I still have 0 idea what's interesting about this. How is this a chess move?
See the "chess notation examples" table. The password doesn't match any chess notation, but it's close enough that it's obviously (to me) intended to be a chess move. In particular, it moves the pawn in front of the queen (in the initial position) forwards two spaces.
Re: Ken Thompson's Unix Password
#228Earlier quoted context omitted.
The guy wasn't fired for the password, he was fired for the sexual harassment of a coworker. And nothing you do on a work computer is secret from your employer. It's not a "private diary" if you're using your employer's hardware.
If he was fired for sexual harassment, that is one thing. But a naughty password on its own? That was maybe not the case here but that is what I have doubts about.
Re: Ken Thompson's Unix Password
#229I'm shocked at how well the old hashing stood up; sure, it's totally crackable today, but a well-picked password still took 4+ days to crack on modern hardware, which is remarkable. (Granted, it doesn't sound like they did anything fancy like throwing a hundred cloud instances at it or something; I'm not saying you should use DES today:) )
30 years ago I cracked everyone’s Unix password on an old Sun computer. It didn’t take long because everyone had a password that was in the dictionary. Needless to say, people were not happy with the messenger.
Re: Ken Thompson's Unix Password
#230Earlier quoted context omitted.
I think it's very interesting how, despite knowing nearly nothing about the situation, everyone here is quick to doubt the victim, and make up scenarios (for which there is zero evidence) where the harasser is the victim.
For all its flaws, innocent until proven guilty is still the fairest justice system. Beyond a reasonable doubt is a high standard of proof. Because we use this standard, it is natural for people to look for reasonable doubts when talking about accusations. That is how western society works. And for very good reasons.
Something obviously bad happens, and everyone falls over themselves to correct and defend not the bad thing that just happened, but a thing they just imagined might happen.
It's a very peculiar (and fairly revealing) thought pattern.