Live data from Hacker News

Ken Thompson's Unix Password

leahneukirchen.org

511–520 of 665 posts

Re: Ken Thompson's Unix Password

#511

I remember cracking the password from a Windows system in high school. There was a centralized login mechanism using Novell but everything was cached locally. So you could boot a Linux CD and copy the password file to a memory stick, and crack at home. I think I used lophtcrack? The head admin account for the entire school district (basically root) had the password “north”. It took like a fraction of a second to crac…

My highschool (well, homeschool resource center) IT admin couldn't log into one of the macs in the A/V lab one day; I heard him talking about it, and being on good terms with him, I offered to try and hack in. I literally googled "how to hack macos password", chanced upon an `nidump` vulnerability recent enough that it hadn't been patched, used that to dump the password hash file, fed that to JTR (compiled on that same machine, to add insult to injury), and almost instantly ended up with the admin password for the entire domain: 1337

It turned out that someone hadn't changed the password, he had just mistyped it over and over again. At the time, I didn't know what "1337" meant, I just thought it was a weird number, and it wasn't until many years later that I suddenly burst into laughter, realizing the "elite" level of security in that lab.

Thanks for the good times, Ron! I'm really glad he just laughed and trusted me as I explored technology instead of freaking out when my portscanners started making the printer spew out a bunch of garbage.

Re: Ken Thompson's Unix Password

#512

Earlier quoted context omitted.

Yeah. My technical tracks were covered. It was the roommate of one of my friends. He overheard me talking about it and ratted me out.

What a punk

That is an understatement. I wonder what kind of backstabber he grew up to be :/

Re: Ken Thompson's Unix Password

#513
post #373

Earlier quoted context omitted.

Agreed. That's why if I were doing it today, I would just shut off the account after the second warning. Although I don't think it's PII if it's all internal company data, especially if it is known that IT will crack your password.

A password is supposed to be very hard to guess by others but not so hard for you to remember so it can be said to be PII! And no, it is not assumed that IT will crack your password. Because how do you know how far IT would go to crack your password and how do you know they are not looking at your data as well? Employee/company officers' email may contain data that could be highly sensitive and something IT should no…

it is not assumed that IT will crack your password

At this company, it was public knowledge that IT will crack your password.

At the vast, vast majority of companies, it's public knowledge that they are looking at your data and email as well. If you are under the impression that your employer doesn't, you should double-check because you are almost certainly wrong.

Re: Ken Thompson's Unix Password

#514

Earlier quoted context omitted.

I was expelled from university for pulling off the exact same exploit with the "workstation only" feature in Novell. In my case, they put a computer in every dorm room, and every single one of them had a domain-wide administrator account cached in its SAM file. It was inevitable that a student would find it. It's been almost 15 years now but I believe the password was rac3c4r or something trivial like that. I ran Oph…

>I never once used it for evil: never read anyone's email, never viewed anyone's private files, never poked around the academic file shares for test solutions, never tried to steal credit card numbers or social security numbers from the finance office's file share. I don't understand this justification. The system owners can't know that to be true and have to proceed as if the systems are compromised. Would you still…

> Would you still feel safe if a burglar broke into your house and left a note saying they didn't take anything?

You might feel safe if he didn’t, but you wouldn’t actually be safe, would you?

Re: Ken Thompson's Unix Password

#515
post #179

Earlier quoted context omitted.

This is a bad analogy.

Actually, it's a rather perfect analogy. People have some expectations of privacy and it's not normally considered acceptable to violate this. Sometimes this stuff is untried in court or falls into a definite legal grey area and usually the policy is to err on the side of caution and simply assume that if something is commonly expected to be private, then it's private and should be kept so. If we were investigating a…

I'm trying to understand what you're saying, but it just seems completely divorced from reality.

Do you believe it has not been tested in the courts that cameras in bathrooms are illegal? Do you believe that if you polled office workers about whether bathrooms are private and whether they expect cameras to be in there, you would get any result other than widespread belief that bathrooms are private and there cannot be cameras in there?

Do you believe it has not been tested in the courts that anything you write on a work computer is the property of the employer? Do you believe that if you polled office workers about whether they think what they do with their work computer is audited or private to them, you would get any result other than widespread understanding that employers own everything you do on your work computer?

Re: Ken Thompson's Unix Password

#516

Earlier quoted context omitted.

> But if the passphrase is already strong (6 random words from the Diceware wordlist), you can use MD5... Is this actually true? Note that you don't need the actual password, just a hash collision.

It doesn't seem like it should be obviously true to me. If the hash algorithm was rot13 it would be pretty easy to determine the password from the hash regardless of the strength of the password

Rot13 is not a hashing algorithm. A hashing algorithm is a one-way function where many entities in the input domain map to the same entity in the output codomain. This means if you have the hash you can't determine the input with out making a guess.

Rot13 is a function with a one to one mapping between the domain and codomain. If you have the output you can apply a function to get the input.

Re: Ken Thompson's Unix Password

#517
post #413

Earlier quoted context omitted.

This is a common refrain, mailing lists do need a lot of instructions at the bottom to make sense — email wasn't made for groups. It's like 'group' SMS, your phone might provide you with a single chat window with all your friends, but what it really is doing is just sending a separate SMS to every one of the recipients. So you need the 'the manual' attached to every message to make sure people get it right. Looks dow…

> email wasn't made for groups I've always wondered why people didn't use newsgroups instead of mailing lists.

Google Groups (kinda) solves this problem. On the viewing side, the app is pretty decent, and then you can still receive / reply through email if desired.

A good example group - https://groups.google.com/forum/#!forum/tiddlywikidev

I wish Apache projects would move more towards something like this.

Re: Ken Thompson's Unix Password

#518

Earlier quoted context omitted.

Like what? I have an ex-girlfriend whom I dumped when she (among other things) called my family and lied about me getting into a horrible accident because we were arguing about her [several hard street drugs] addiction. I cared about her enough to stick around until after the drug problems started. She tells people I'm a "creep" when she explains why we didn't work out, because we had been together for a while and I…

I'm sorry that happened, that sounds like a terrible situation. Do you see how I took you at your word and extended sympathy, rather than questioning whether you're misrepresenting the situation? Is there something you know about the facts of jedberg's situation that lead you not to do the same?

He has not presented any facts that are under contention, only normative estimations that rely on facts that are deliberately unspecified.

The politically and economically safe option in the workplace is always to discard people who fall under scrutiny that exposes an employer to liability. This raises the reasonable standard of complaint for these types of issues beyond "his password, which I cracked despite design and goal to remain private to one human soul ever, was weirdly suggestive, and none of the people ostensibly involved have voiced any concerns but I must Report This to The Authorities and Start the Hammer Falling."

Suspicion and doubt are very powerful weapons, and sometimes they're used against good people in the name of heroism, saying nothing of bad motives. They also have the feature of being incredibly hard to dispel entirely once raised, regardless of the quality or scale of the evidence. If someone looked at my F-word password with the wrong prior or coaching, I'd have to break out volumes of psychotic voicemails, videos, pictures, testimony by family and close former friends, etc, to prove I shouldn't be Cancelled.

Can you think of a crackable-length passphrase that would make a normal, level-headed person suspicious enough to make efforts that almost guarantee someone is going to get fired in the worst way possible?

Re: Ken Thompson's Unix Password

#519
One lone password from the original list, Bill Joy's password, is still uncracked as far as I can tell. Bill Joy is the co-founder of Sun Microsystems, author of vi, and a key developer of BSD UNIX. He apparently picked the best password.

Here's the /etc/passwd entry:

  bill:.2xvLVqGHJm8M:8:10:& Joy,4156424948:/usr/bill:/bin/csh

Re: Ken Thompson's Unix Password

#520
post #483

Earlier quoted context omitted.

Our high school network ran on Novell NetWare, but I wasn't anywhere near smart enough to crack anything so I just wrote a little program in QBASIC that looked like the NetWare login prompt which rejected all login attempts but dumped what was entered into a text file, and left it running on one of the PCs in the computer room. It wasn't even a compiled program, it was just running inside QBASIC's IDE. Yet it was run…

This is exactly why some versions of Windows required you to press ctrl-alt-delete to open the login form. Programs aren't allowed to block Windows from receiving ctrl-alt-delete, so a fake login program would not be able to stay on the screen after the user pressed ctrl-alt-delete. (Of course this only works if the user knows to always hit ctrl-alt-delete when they go to login. If the user sees an already-open (fake…

The new Windows 10 login screen doesn't seem to support anything running on it, all I've seen is a duo security prompt that A. Only showed up after a login and B. Doesn't work on Windows 10 in a non-rdp session on a Microsoft account[0]. Sadly this also means you can't run something like Wallpaper Engine on the lock screen[1].

0: https://duo.com/docs/rdp-faq#can-i-use-duo-with-a-microsoft-...?

1: https://steamcommunity.com/app/431960/discussions/0/15001264...

Post reply on HN