17.3 MILLION MD5 hashes (unsalted, not that it matters), of which over 16 million have already been cracked.
What?! This means next leak will be one million CRC32 password hashes? Or maybe LM hashes. Or crypt on old /etc/password files
Change your Last.fm password
21–30 of 152 posts
Re: Change your Last.fm password
#22Earlier quoted context omitted.
They're all Hadoop users.
I doubt their Hadoop clusters have password data stored in them.
Re: Change your Last.fm password
#23Re: Change your Last.fm password
#24Re: Change your Last.fm password
#25Do LinkedIn, eHarmony and LastFM have any parts of their software stack in common? Same 0day?
Re: Change your Last.fm password
#26Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…
Do you use the same password/username combination somewhere else? If not, good for you. You're kind of a rare person.
Re: Change your Last.fm password
#27Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…
Re: Change your Last.fm password
#28Passwords need to die. There will always be bad implementations on storing passwords and those will hurt many users. We need something better.
The problem, of course, is a lot of sites still don't support OpenID.
Re: Change your Last.fm password
#29Re: Change your Last.fm password
#30Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…
They'll get your username, they might crack your password. Do you use the same password/username combination somewhere else? If not, good for you. You're kind of a rare person.