Live data from Hacker News

Change your Last.fm password

thenextweb.com

31–40 of 152 posts

Re: Change your Last.fm password

#31

Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…

It matters because there was a failure and it could be in a technology or service you also use.

It matters because many users re-use credentials.

Scenario: You send a confidential email to a colleague, colleague has her lastfm compromised. Attacker scripts up logins against all common sites - including her Gmail account where you sent your confidential email. Script not only logs in and changes password, it also forwards to her friends and family all the emails containing some target phrases - including your confidential one.

Re: Change your Last.fm password

#32
post #8

Do LinkedIn, eHarmony and LastFM have any parts of their software stack in common? Same 0day?

More probably the same mindset regarding security. I wouldn't expect a company that stores unsalted passwords to invest much in security elsewhere.

Re: Change your Last.fm password

#33

Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…

But how many people have throwaway passwords on sites like these? It might not mean much to the tech-savvy community, but I'm sure a lot of people use the same password for a lot of services.

They might not be able to do much with your account on Last.fm, but they have your email, for which you may or may not use the same password.

Re: Change your Last.fm password

#34
post #27

Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…

I have over 150k songs scrobbled to Last.FM and have been a member since 2005. I actually can think of very few other services that I would care as much as if my Last.FM was compromised/deleted.

I can see it now...

Show HN: pclark listens to Miley Cyrus, A LOT.

Re: Change your Last.fm password

#35
post #26

Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…

They'll get your username, they might crack your password. Do you use the same password/username combination somewhere else? If not, good for you. You're kind of a rare person.

I reuse passwords for websites like that, but the other places I use it are similarly throwaway.

Re: Change your Last.fm password

#36

Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…

Most people reuse passwords across services. If that's the case, a breach in any one service becomes a foothold into a panoply of other accounts.

Re: Change your Last.fm password

#37
post #27

Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…

I have over 150k songs scrobbled to Last.FM and have been a member since 2005. I actually can think of very few other services that I would care as much as if my Last.FM was compromised/deleted.

Same. 127k songs since '05, and I still cruise through the site regularly and look at what i was listening to on this day in 20xx.

I briefly paid for the site's radio functionality before it was crippled. It feels to me like they've died a similar death to Flickr (acquired, core team left, innovation stopped). Such a shame.

Re: Change your Last.fm password

#39
post #27

Earlier quoted context omitted.

I have over 150k songs scrobbled to Last.FM and have been a member since 2005. I actually can think of very few other services that I would care as much as if my Last.FM was compromised/deleted.

Same. 127k songs since '05, and I still cruise through the site regularly and look at what i was listening to on this day in 20xx. I briefly paid for the site's radio functionality before it was crippled. It feels to me like they've died a similar death to Flickr (acquired, core team left, innovation stopped). Such a shame.

Agreed. Last.FM is such a trove of data. It is fascinating to see what I was listening to and when, and especially looking at macro events and seeing how that influenced the worlds listening habits.

It took Last.FM until 2012 to implement the ability to find your friends from Facebook. Seriously. It really is such a shame; they're a service that needs to be spun out.

Re: Change your Last.fm password

#40
post #26

Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…

They'll get your username, they might crack your password. Do you use the same password/username combination somewhere else? If not, good for you. You're kind of a rare person.

Yes. That's the point.

Not only will they be able to listen to music that I like, they might be able to download MySQL as though they were me or comment on Engadget articles as me.

None of which are particularly concerning. Because those are throwaway accounts for me.

Post reply on HN