Live data from Hacker News

Ken Thompson's Unix Password

leahneukirchen.org

351–360 of 665 posts

Re: Ken Thompson's Unix Password

#351
post #235

Earlier quoted context omitted.

Doubt it. It took 4 days for just one top of the line GPU. Any dedicated attacker will have farms to parallelize it even further. It’s not exactly linear, but with just 4 GPUs (~$4000; well within the reach of any dedicated attacker), that’s one day. Not to mention the fact that GPUs have still been roughly following Moore’s Law in terms of performance. It’s probably safe from the casual attacker who just downloads a…

> If I can crack a DES password in 4 days, I can crack a 3DES password in 12 It's multiplicative, not additive. 3DES is about 2^56 times as difficult to crack as DES. (Not 2^112 times because there is an attack that effectively limits it to twice the effective bits of DES, rather than the three times you might expect at first).

> It's multiplicative, not additive. 3DES is about 2^56 times as difficult to crack as DES. (Not 2^112 times because there is an attack that effectively limits it to twice the effective bits of DES, rather than the three times you might expect at first).

If you’re using 3 different keys, yes, that makes sense. But if you’re just keystretching one key, wouldn’t it just take 3 times as long because you encrypt, decrypt, encrypt (3 processes)?

Re: Ken Thompson's Unix Password

#352

I had a password for an old school system (which I wrote) that was "any 21 characters where the 21st character is a 'z'". People would watch me type it (mashing 20 keys then the 'z') and be amazed I could remember a password that long.

I discovered that's the way my banking app actually worked until only a few updates ago. The password was originally limited to 8 characters (why this was the case for an online bank password is beyond me) but the app would allow you to enter more characters into the password input. It only accepted the first 8 characters though so anything you entered after those was ignored. I discoveres this when I mistyped my pas…

When I was living in Puerto Rico for work, the local credit union I was using had this same problem. Although the tooltip and messaging on the page said 8-16 chars, only the first 8 were used, and from my testing it had to be case insensitive.

I promptly updated my direct deposit with my employer and used my more secure off-island bank as the destination for the majority of my pay, and had only the minimum required to avoid fees and act as spending money put in that acct.

Re: Ken Thompson's Unix Password

#353

Earlier quoted context omitted.

It's stated that he was fired for "being creepy", which is a highly underspecified complaint that can be used against someone you find disagreeable for any reason, only some of which warrant termination-of-livelihood. I was being charitable assuming that the real accusation involved actually harassing someone.

I said "being creepy" because I was being vague. He was doing much worse than that.

Like what? I have an ex-girlfriend whom I dumped when she (among other things) called my family and lied about me getting into a horrible accident because we were arguing about her [several hard street drugs] addiction. I cared about her enough to stick around until after the drug problems started. She tells people I'm a "creep" when she explains why we didn't work out, because we had been together for a while and I seemed like a decent guy. I literally moved to a different state because she'd show up at my home and work frenzied, and I knew a restraining order would land her in jail (and cause her to lose her surprisingly good job, which I was sure was the last remaining foothold of stability in her life; at this point I was literally worried about indirectly killing her by protecting myself). She still doesn't know where I live, some of my throwaway accounts have the phrase "FUCK [her name]" in their password, and (old, because I can't share contact anymore) mutual friends have told me she tells everyone that I developed hardcore schizophrenia and generally behaved like Satan. The shorthand for this is "creep".

Re: Ken Thompson's Unix Password

#354
post #281

Earlier quoted context omitted.

A better pattern is something long that will exceed the bounds of a rainbow table. I love JavaScript but I really wish it didn't have the ASI feature* The example is 67 characters long written in a statement that is easy to remember with two non-alpha characters aside from the spaces. Imagine the size of rainbow table it would take to crack that.

I'm not sure how easy that is to remember... Was it 'really love but wish' or 'love but really wish'? etc.

I suspect you would word your password in a way that is most familiar for you. The idea is to achieve both cognitive comfort while destroying brute force efforts. A better example:

    Antidisestablishmentarianism is the longest English word I can think of##
73 characters.

Re: Ken Thompson's Unix Password

#355
post #53
post #8

Earlier quoted context omitted.

The part before : is the hash, the part after is the cracked 8 character password.

Honestly, that confused me too. I really thought the whole password was that long.

Same here, thought it strange they could brute-force such a long password! Even with MD5.

Re: Ken Thompson's Unix Password

#356

Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…

I'm conflicted about this. I know I'd be pretty upset if an employer starting talking to me about a plaintext password that's supposed to be hashed. The problem is that they brute forced it and then sent it directly off to HR? Yes, as a sysadmin it's perfectly acceptable to be searching for weak passwords, but reading the plaintext yourself for fun then scurrying to HR is kinda a slimy thing to do. As an admin you ha…

How is that slimy? You have no expectation of privacy at work. The company owns everything. They not only own it but they monitor everything that’s done on their devices.

If you don’t want something read by your employer don’t do it with company property or on their WiFi. It’s a rule I live by and I never connect any personal device to my company’s guest WiFi.

Re: Ken Thompson's Unix Password

#357

I'm shocked at how well the old hashing stood up; sure, it's totally crackable today, but a well-picked password still took 4+ days to crack on modern hardware, which is remarkable. (Granted, it doesn't sound like they did anything fancy like throwing a hundred cloud instances at it or something; I'm not saying you should use DES today:) )

And "Good news — no pwnage found!" On Troy Hunt's https://haveibeenpwned.com/Passwords

Which shows that it is fairly strongly "unique", since no-one else has used it and been pwned (or he hasn't reused it and been pwned).

Re: Ken Thompson's Unix Password

#358

Earlier quoted context omitted.

This is what I thought too, the heat simply becomes overwhelming and the unit has to underclock to prevent melting.

I think the "towards the end" part is the misleading one. The software has no idea where the end is or it would just jump there. Since the run took 4 days slowing down due to throttling would happen pretty fast as the card reaches a thermal equilibrium. Certainly wouldn't take days to do it. It's more likely the explanation above of something (not heat) accumulating over time and slowing down the processing.

Real explanation below >> https://news.ycombinator.com/item?id=21205272

Re: Ken Thompson's Unix Password

#359
post #253

Earlier quoted context omitted.

You know, it's quite possible for multiple people to be "wrong" in a given situation. It's possible both the employee and the sysop to be wrong.

I agree, - but morality is sticky and complex. It was obviously wrong to be the creepy sexist. In the abstract sense, it is wrong to invade privacy. But then, if in your invasion of privacy you uncover a wrongdoing, the right thing to do is report it. It would be wrong to read the CFO's email inbox, and probably illegal. But then if you uncover they are committing fraud, you need to report it to police, as well as co…

I get what you're saying here but:

>In the abstract sense, it is wrong to invade privacy.

You have no real expectation of privacy when using company owned equipment. This was almost certainly spelled out to the employee in question in the acceptable use policy he agreed to upon being hired. Companies have to operate this way so they can investigate computers if compelled to by court or law, and so they can recover important information off computers when the user exits the company.

If he was using a BYOD computer I'd have a different opinion on the matter.

Post reply on HN