Live data from Hacker News

Ken Thompson's Unix Password

leahneukirchen.org

471–480 of 665 posts

Re: Ken Thompson's Unix Password

#471
post #428

Earlier quoted context omitted.

> innocent until proven guilty is still the fairest justice system Justice system administered by a state where the repercussions include imprisonment and death - absolutely. But HR is not a judicial system and should not be viewed as one. I think I take your point to be just a descriptive observation of "our social discussion reflects a habit based on our exposure to judicial systems" and not a normative statement.…

Given the US's employer-based health care system, HR can sentence some people to death.

That's a fair point. And we should rectify that by fixing our healthcare system, not by making it harder for assault survivors.

Re: Ken Thompson's Unix Password

#472

I remember cracking the password from a Windows system in high school. There was a centralized login mechanism using Novell but everything was cached locally. So you could boot a Linux CD and copy the password file to a memory stick, and crack at home. I think I used lophtcrack? The head admin account for the entire school district (basically root) had the password “north”. It took like a fraction of a second to crac…

I was expelled from university for pulling off the exact same exploit with the "workstation only" feature in Novell. In my case, they put a computer in every dorm room, and every single one of them had a domain-wide administrator account cached in its SAM file. It was inevitable that a student would find it. It's been almost 15 years now but I believe the password was rac3c4r or something trivial like that. I ran Oph…

Do you know how they ended up finding out about it and catching you?

Re: Ken Thompson's Unix Password

#473
post #461

Earlier quoted context omitted.

> It is not very different from writing something naughty in a private diary, or even thinking a naughty thing. I don't know if I'm too normal or what, but my gut feeling is that yes it's really creepy. And all these things have different creepiness to them. Thinking a naughty thing is the least creepy. A private naughty diary is starting to be creepy. If it's just a passage in a normal diary, it's not too bad, if th…

I think there is a big difference between expressing your thoughts from having them. I am quite certain that more or less everyone harbors thoughts that would not be socially acceptable to state to someone in the workplace, but they are completely normal (as in common) thoughts. It is not creepy to have them. It is expressing them to someone that would cross the boundary.

I think we agree then, these things have varying degrees of creepiness, with thoughts being the least creepy. And comparing having a thought to having it be your password, as OP did, is a false equivalence fallacy, from my perspective. One is order of magnitude weirder than the other.

Re: Ken Thompson's Unix Password

#475

Earlier quoted context omitted.

Yea historically the SAM file on windows has always been a weak spot because of its NTLM hashing scheme. By breaking passwords larger than 7 letters into multiple sub-password hashes it virtually guaranteed rainbow tables would destroy its security.

Out of curiosity, why did they do this? Was hashing super computationally expensive when NTLM first appeared (NT 3.51 I think?)

I wonder if it’s for export control. 7 chars x 8 bits = 56 bits. This used to be the limit for max size of symmetric keys by the US.

Re: Ken Thompson's Unix Password

#476
post #435
post #389

Earlier quoted context omitted.

Its quite truthworthy. Its run by Troy Hunt (known security researcher) and : "When you search Pwned Passwords The Pwned Passwords feature searches previous data breaches for the presence of a user-provided password. The password is hashed client-side with the SHA-1 algorithm then only the first 5 characters of the hash are sent to HIBP per the Cloudflare k-anonymity implementation. HIBP never receives the original p…

My only concern with the site is some privacy implications. I entered a friend's email just to check for him and it wasn't validated at all, and I found out a few sites he had accounts with. Nothing too concerning was revealed, but privacy for its own sake is a valid goal IMO.

As far as I know hibp specifically hides sensitive breaches (such as the Ashley Madison one) to non-verified access. Also, he basically only shows public data; your privacy was already gone back when the original company failed to secure their servers.

Re: Ken Thompson's Unix Password

#477
post #461

Earlier quoted context omitted.

I think there is a big difference between expressing your thoughts from having them. I am quite certain that more or less everyone harbors thoughts that would not be socially acceptable to state to someone in the workplace, but they are completely normal (as in common) thoughts. It is not creepy to have them. It is expressing them to someone that would cross the boundary.

I think we agree then, these things have varying degrees of creepiness, with thoughts being the least creepy. And comparing having a thought to having it be your password, as OP did, is a false equivalence fallacy, from my perspective. One is order of magnitude weirder than the other.

[deleted]

Re: Ken Thompson's Unix Password

#478
post #332

Earlier quoted context omitted.

> It is not very different from writing something naughty in a private diary, or even thinking a naughty thing. I don't know if I'm too normal or what, but my gut feeling is that yes it's really creepy. And all these things have different creepiness to them. Thinking a naughty thing is the least creepy. A private naughty diary is starting to be creepy. If it's just a passage in a normal diary, it's not too bad, if th…

I think if it was really literally just the password, it would be pretty weak grounds to fire someone. But OP says he was being deliberately vague so as not to be specific about the situation, and there was a lot more going on. The guy got fired for his actions, not his password. The password was just a tipping point.

I'm not really talking about the firing, I had another comment elsewhere about that part. And I could excuse only the password, because one creepy behavior can be excused, a recurring number of them not so much. I still need to excuse the password though, because I think that's just creepy. If it was just normal behavior, it wouldn't need excusing, it just wouldn't even be an argument.

I'm more saying that having your work password be a naughty fantasy involving your coworker is just plain creepy. I've never heard of this. I mean, even having a naughty fantasy involving your partner as your work password is creepy. How can anyone think this is totally normal and appropriate behavior? I know my wife would find it real weird if that was my password.

If you do that, and are starting to feel like other people find you creepy or are suggesting you might be, and you're confused why they think that.. I just don't know what to say. If you were under the impression having such a password is common, I'm afraid you were mistaken.

But, like I said, I'm giving people an opening here.. maybe I'm the one that's mistaken, and naughty sexual fantasies with coworkers as work passwords is a very common and normal choice of password. Presented with such evidence, I'd reconsider.

Re: Ken Thompson's Unix Password

#480
post #435

Earlier quoted context omitted.

My only concern with the site is some privacy implications. I entered a friend's email just to check for him and it wasn't validated at all, and I found out a few sites he had accounts with. Nothing too concerning was revealed, but privacy for its own sake is a valid goal IMO.

As far as I know hibp specifically hides sensitive breaches (such as the Ashley Madison one) to non-verified access. Also, he basically only shows public data; your privacy was already gone back when the original company failed to secure their servers.

Understood, it's a small complaint, the data is already out there on the web and it's not his fault. But there is value in aggregation or the site wouldn't exist. It makes it easier to just put a few emails in there and see what shows up for fun or malice.

It's great that sensitive breaches are apparently hidden but I'd be wary of judging for other people what is sensitive. Some like Ashley Madison are obvious, others less so.

Post reply on HN