Live data from Hacker News

Change your Last.fm password

thenextweb.com

21–30 of 152 posts

Re: Change your Last.fm password

#21
post #2

17.3 MILLION MD5 hashes (unsalted, not that it matters), of which over 16 million have already been cracked.

What?! This means next leak will be one million CRC32 password hashes? Or maybe LM hashes. Or crypt on old /etc/password files

This was funny, and I laughed, but the irony is that old Unix crypt(3) is probably better than MD5 or SHA1.

Re: Change your Last.fm password

#22
post #17
post #9

Earlier quoted context omitted.

They're all Hadoop users.

I doubt their Hadoop clusters have password data stored in them.

It would be very foolish, but I do wonder if they used Hadoop to compare their hashes with publicly exposed hashes after breaches of other sites (for example, Gawker or Zappos) in order to force reset affected users.

Re: Change your Last.fm password

#24
post #2

17.3 MILLION MD5 hashes (unsalted, not that it matters), of which over 16 million have already been cracked.

What?! This means next leak will be one million CRC32 password hashes? Or maybe LM hashes. Or crypt on old /etc/password files

Well, the Gawker hack was DES IIRC.

Re: Change your Last.fm password

#26

Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…

They'll get your username, they might crack your password.

Do you use the same password/username combination somewhere else? If not, good for you. You're kind of a rare person.

Re: Change your Last.fm password

#27

Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…

I have over 150k songs scrobbled to Last.FM and have been a member since 2005. I actually can think of very few other services that I would care as much as if my Last.FM was compromised/deleted.

Re: Change your Last.fm password

#28
post #5

Passwords need to die. There will always be bad implementations on storing passwords and those will hurt many users. We need something better.

I like using OpenID. I just use my domain name as a delegate and point it at my current OpenID provider of choice for authentication (which is currently my Google profile; used to be myOpenID 'til they went down for 1/2 a day). As long as I retain my domain name, I can control authentication, even if my current provider were to be compromised (just point my domain name/delegate at a different provider).

The problem, of course, is a lot of sites still don't support OpenID.

Re: Change your Last.fm password

#29
post #2

17.3 MILLION MD5 hashes (unsalted, not that it matters), of which over 16 million have already been cracked.

What?! This means next leak will be one million CRC32 password hashes? Or maybe LM hashes. Or crypt on old /etc/password files

ROT13?

Re: Change your Last.fm password

#30
post #26

Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…

They'll get your username, they might crack your password. Do you use the same password/username combination somewhere else? If not, good for you. You're kind of a rare person.

Even if you don't use the same username, if they have your email, those are fungible with usernames on many sites. (And of course game over if you use the same or similar password for Last.fm and email.)
Post reply on HN