Live data from Hacker News

Ken Thompson's Unix Password

leahneukirchen.org

631–640 of 665 posts

Re: Ken Thompson's Unix Password

#631

Earlier quoted context omitted.

Wait, how is it a common / weak password if it has some oddly sexual phrase regarding a specific person? Sounds like its literally just brute-forcing, in which case you're just going to hit random user's passwords.

A string of dictionary words and a very common name. And yeah, JohnTheRipper was a brute forcing dictionary attack that was very common. If anyone had access to the password file they could run the same cracker. The idea was to crack the passwords before an advisary could using the same tools.

Next time you can push for explicit password quality requirements and something like 2FA instead of violating people's privacy and weakening their security at the same time. (Can you imagine anyone reused personal passwords?) This eagerness to apply fun tools in the workplace is in large part what built the heinous surveillance apparatus that's probably going to kill a lot of people as soon as a sufficiently strong-willed fascist takes control again. Richard Stallman has called this "Stalin's dream", but ironically he was also recently Cancelled for ridiculous allegations of sexual misconduct and wrong-think, so perhaps this allusion is not sufficiently powerful for this audience anymore. A shame if so.

Re: Ken Thompson's Unix Password

#632
post #196

Earlier quoted context omitted.

I think it's very interesting how, despite knowing nearly nothing about the situation, everyone here is quick to doubt the victim, and make up scenarios (for which there is zero evidence) where the harasser is the victim.

Because the evidence is extremely weak and the reason cited for him being axed was he was a "creep"? Pretty subjective in my eyes without other information provided. There's a mile wide difference between being a weirdo mouth-breathing creep, and actually sexually harassing someone.

Reply (can't edit now): I know my above post seems like an asshole. That isn't my aim. I'm simply posing a necessary question before we instinctually start up the crucifixion process. Ruining peoples lives with scant evidence scares me regardless of the who/where/what/when.

Re: Ken Thompson's Unix Password

#633

Earlier quoted context omitted.

"Any sufficiently complicated group communication system contains an ad-hoc, informally-specified, bug-ridden, slow implementation of half of Usenet."

I wish. Over Microsoft Teams, I would take that any day of the week.

Like I said: "bug-ridden, slow" :)

Re: Ken Thompson's Unix Password

#634
post #155

I still have 0 idea what's interesting about this. How is this a chess move?

the password is the last part: p/q2-q4! it's a notational way in the chess program (written by Ken Thompson) to describe a chess move, "pawn from Queen's 2 to Queen's 4." A very common opening move that "puts a pawn in the center, controlling the important e5-square, and opens the line for the Bc1."[1] The notation is old. Modern notation would just write it as "d4" because there's only one piece (a pawn) who can mov…

p/q2-q4!

Re: Ken Thompson's Unix Password

#635

Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…

>* One guy actually got fired for his password. He was already being super creepy and making the girl who sat across from him uncomfortable, but she never told anyone. Then we cracked his password, which was a very naughty phrase about the girl who sat across from him. I reported it to HR, who asked the girl, who then said he was creepy, and so they acted swiftly on the reports and got him out of there.* So, he never…

"Think of her comfort!" is the lonely childless Bay Area man's version of "Think of the children!"

Re: Ken Thompson's Unix Password

#636

Earlier quoted context omitted.

We have a high standard for guilt in court because someone's freedom and perhaps life is on the line. You as a private citizen have a right to make decisions on less than a drawn-out court case and a sequestered jury. So, in the eyes of the criminal courts, yes, OJ is still innocent. But would you have him babysit your kids based only on a reasonable doubt he's a multiple murderer?

> You as a private citizen have a right to make decisions on less than a drawn-out court case and a sequestered jury. That's true, but it doesn't make my opinions morally justified. But my point wasn’t about the verdict--the court’s, mine, or the public’s. It was that it is wrong to presume guilt anywhere—in court or in personal opinion—on the basis of a charge alone. (In OJ's case, we're all far past that, so I thin…

I literally didn't bring up OJ. I was using the example already in use in the thread when I replied. The question, in a generic sense, is if you have two equally qualified candidates one of whom is acquitted and one of whom nobody's accused of wrongdoing, would you flip a coin or hire the one never accused?

Re: Ken Thompson's Unix Password

#637

Earlier quoted context omitted.

> You as a private citizen have a right to make decisions on less than a drawn-out court case and a sequestered jury. That's true, but it doesn't make my opinions morally justified. But my point wasn’t about the verdict--the court’s, mine, or the public’s. It was that it is wrong to presume guilt anywhere—in court or in personal opinion—on the basis of a charge alone. (In OJ's case, we're all far past that, so I thin…

I literally didn't bring up OJ. I was using the example already in use in the thread when I replied. The question, in a generic sense, is if you have two equally qualified candidates one of whom is acquitted and one of whom nobody's accused of wrongdoing, would you flip a coin or hire the one never accused?

> would you flip a coin or hire the one never accused?

I'd try to do neither. The reality is, no one is equally qualified because no one is identical to anyone else. There are always tradeoffs.

But I'd try to weigh those tradeoffs without being swayed either way by the fact that someone was once accused and later acquitted. Personally, I'm not even sure whether I'd be more or less likely to want to hire a person on the basis of that detail; I really think it's not evidence of anything.

It's like the influence of an independent variable Y in the logical formula "X implies Z", or like a "don't care" cell in a Karnaugh map -- it signifies nothing.

Re: Ken Thompson's Unix Password

#638

Earlier quoted context omitted.

> The politically and economically safe option in the workplace is always to discard people who fall under scrutiny that exposes an employer to liability. What leads you to believe this? You are aware, I assume, of the existence of "wrongful termination" lawsuits, many of which have cost companies millions of dollars? > Can you think of a crackable-length passphrase that would make a normal, level-headed person suspi…

Three responses in turn, 1. The courts are profoundly unfair. Are you comfortable forcing harassment victims to go through the courts for what are literally criminal allegations? 2. This example seems too contrived and implausible, as is anything else I could think of. The whole story just seems too magical. Maybe I'm just being hard-headed and arguing with a hero. 3. I will concede that is a more unpleasant series o…

1. I have no idea what you're talking about. You suggested the liability risk for employers is extremely one-sided such that the "safe option ... is always to discard people". I asked if you were aware of the enormous, court-tested liability risk employers face when they discard people. What leads you to believe the liability risk is nevertheless extremely one-sided?

2. Someone sexually harassing his coworker and saying something sexual about her in his password seems magical and unlikely to you? You don't believe the hundreds of corroborated stories about men saying stuff like that openly? Or you think people are less likely to do that in something semi-private like a password than openly?

Re: Ken Thompson's Unix Password

#639

Earlier quoted context omitted.

Three responses in turn, 1. The courts are profoundly unfair. Are you comfortable forcing harassment victims to go through the courts for what are literally criminal allegations? 2. This example seems too contrived and implausible, as is anything else I could think of. The whole story just seems too magical. Maybe I'm just being hard-headed and arguing with a hero. 3. I will concede that is a more unpleasant series o…

1. I have no idea what you're talking about. You suggested the liability risk for employers is extremely one-sided such that the "safe option ... is always to discard people". I asked if you were aware of the enormous, court-tested liability risk employers face when they discard people. What leads you to believe the liability risk is nevertheless extremely one-sided? 2. Someone sexually harassing his coworker and say…

1. It's difficult to safely discard people on the basis of their belonging to a certain set of protected classes, which does not include those accused of sexual misconduct. As soon as you have someone willing to issue a complaint you can't disprove, you're prepared to safely remove your enemies. There's a reason savvy managers never have private meetings with women.

2. It's magical that some guy exposed a "creep" Doing Very Bad Things by looking at his password he cracked. No witnesses complained, the victim had never complained, just from a distant computer we catch this faint whiff of something wrong in the strangest (invasive, aside) way and turn out to be a hero. Or maybe we just sent a weird password to HR, and they did the default thing and fired the guy for nuisance and liability, and years later we remember the justification that he must have deserved it because he's gone. (Details? Sorry, can't!) It's easier on the conscience, too.

Re: Ken Thompson's Unix Password

#640
Dear stargrave, I am very grateful for sharing this knowledge. It was a delight reading.With this, I realized I am almost achieving a old dream of mine since my teenager years: I understood almost everything. And came in the proper time, just as I am finishing my masters in informatics and computer engineering this year. You have my gratitude.
Post reply on HN