Live data from Hacker News

Change your Last.fm password

thenextweb.com

121–130 of 152 posts

Re: Change your Last.fm password

#121
post #71
post #27

Earlier quoted context omitted.

I have over 150k songs scrobbled to Last.FM and have been a member since 2005. I actually can think of very few other services that I would care as much as if my Last.FM was compromised/deleted.

Ditto. 196k since '05 here. The ability to see how my musical taste synced with the ebb and flow of my life is something I really cherish.

29k since September 2004, and I listen to an album almost every day.

You're scrobbling songs during your whole work day, right? I disable it at work, since I don't pay much attention and end up with lots of plays I don't care much about.

(edit: my average is really 10 songs/day!).

Re: Change your Last.fm password

#122
I doubt my new password will be any safer, so I can't really use one which follows my current pseudo-random patterns.

I'm now convinced that password managers, with random generated passwords, are the way to go. At least they have a strong incentive to focus on protecting user data. Still scared of not knowing my own passwords, and giving them to a third party, though.

Re: Change your Last.fm password

#123
post #90

Earlier quoted context omitted.

I've just spent the last couple of hours creating unique longins for every site I can remember having a login for and storing them in Keepass (opensource password safe). The Keepass database is stored on my dropbox account so it's automatically synced to all machines / devices I use. I get the impression this is going to be a bit of a PITA, but with the rate these sites are being breached it's probably a sensible mov…

FWIW, I did this a few years back (with 1Password, after having used Password Gorilla for a while). With the browser integration 1Password (and, I think keypass and lastpass) use, I think it's actually a productivity plus rather than a PITA...

Concur: I use 1password and lastpass. There are a couple of critical accounts that are actually wrong in each (non-overlapping) and a couple I still only have in my head, but overall it's a huge plus on a day-to-day basis. And it's an incredible relief to read these announcements, pull up my password for that site, and see it's 20 random characters that I know aren't useful on any other site.

Re: Change your Last.fm password

#124

Earlier quoted context omitted.

On the other hand, it's much harder to crack a hashed thumprint image. [edit] evan_ is right, you don't hash scan images. The question is, how much usable bits of entropy you can extract from a thumbprint scan? Anyway, I retract my main point.

Definitely. A 256 x 256 pixel grayscale image (8 bits per pixel) is half a million bits of entropy... try cracking that on your botnet! Although the real entropy of thumbprint images is likely to be much smaller, considering that they share many simliar pixels... but it's still unimaginably huge compared to a short alphanumeric password.

Draw a picture on a piece of paper. Sign it, write your name, arbitrary words, whatever. Hold it up to a camera.

Could something like this be made to work? Work in the sense that a variety of cameras could read the same "password"? I guess QR codes have a fair bit of redundancy built-in...

Re: Change your Last.fm password

#125

Jeepers, I just changed my linked in password. I had the source for PGP back in 1993, I don't recycle passwords for anything remotely important, I use gnarly long passphrases, two factor authentication and what-all else, and I AM SICK OF IT. I'm beginning to think that IBM had the right idea witht he thumbprint scanners in the laptops. I'm tired of the maintenance security imposes on me, the lack of a meaningful indu…

Funnily enough I opened a new bank account the other day (Chase) and to my surprise they don't allow special characters to be used in the passwords. It indeed appears that the entire system is broken beyond repair. It seems like it is becoming the norm to expect to be exploited at some point so the de-facto preemption is to have someone to blame. As the manager of a datacenter we recently moved into said "we're here…

TD Bank is the same, maximum is eight characters and no special characters for the password.

I spoke to them and got a flustered "Well would you like me to mention that to our IT department?"

It's only been like that for 15 years maybe they should look into it!

Re: Change your Last.fm password

#126
post #27

Last.fm sounds like the canonical example of a site that where it makes absolutely no difference if your password gets exposed. Worst case, some malicious individual on the internet will learn that I still like the Beastie Boys, even though it's not 1994 anymore. And possibly they'll listen to music in my name. This is why one has a throwaway password. For throwaway accounts at throwaway sites like this. Getting your…

I have over 150k songs scrobbled to Last.FM and have been a member since 2005. I actually can think of very few other services that I would care as much as if my Last.FM was compromised/deleted.

Same feelings. I treasure my last.fm stats so much. It has documented 7 years of my life in a way that no other site or social network could express.

Re: Change your Last.fm password

#127
post #87

Earlier quoted context omitted.

On the other hand, it's much harder to crack a hashed thumprint image. [edit] evan_ is right, you don't hash scan images. The question is, how much usable bits of entropy you can extract from a thumbprint scan? Anyway, I retract my main point.

two thumbprint scans, even one right after another, won't be identical, so comparing hashes is pointless.

https://www.tineye.com/faq#how

Re: Change your Last.fm password

#128

Earlier quoted context omitted.

Funnily enough I opened a new bank account the other day (Chase) and to my surprise they don't allow special characters to be used in the passwords. It indeed appears that the entire system is broken beyond repair. It seems like it is becoming the norm to expect to be exploited at some point so the de-facto preemption is to have someone to blame. As the manager of a datacenter we recently moved into said "we're here…

TD Bank is the same, maximum is eight characters and no special characters for the password. I spoke to them and got a flustered "Well would you like me to mention that to our IT department?" It's only been like that for 15 years maybe they should look into it!

I receive spam (not marketing crap, but pump-and-dump penny stock fraud spam) at an email address I created only for use at TD. Either they sold their email database to spammers, or they got hacked and failed to disclose it.

Re: Change your Last.fm password

#129

Earlier quoted context omitted.

Funnily enough I opened a new bank account the other day (Chase) and to my surprise they don't allow special characters to be used in the passwords. It indeed appears that the entire system is broken beyond repair. It seems like it is becoming the norm to expect to be exploited at some point so the de-facto preemption is to have someone to blame. As the manager of a datacenter we recently moved into said "we're here…

TD Bank is the same, maximum is eight characters and no special characters for the password. I spoke to them and got a flustered "Well would you like me to mention that to our IT department?" It's only been like that for 15 years maybe they should look into it!

I receive spam (not marketing crap, but pump-and-dump penny stock fraud spam) at an email address I created only for use at TD. Either they sold their email database to spammers, or they got hacked and failed to disclose it.

Re: Change your Last.fm password

#130
post #31

Earlier quoted context omitted.

It matters because there was a failure and it could be in a technology or service you also use. It matters because many users re-use credentials. Scenario: You send a confidential email to a colleague, colleague has her lastfm compromised. Attacker scripts up logins against all common sites - including her Gmail account where you sent your confidential email. Script not only logs in and changes password, it also forw…

anyone care to bet everyone with a linkedin account who works at a tech company just got targetted attacks? Hi, my name is Joe Hacker, and I work at ! Since you got my linkedin account, why not try that password at admin. ?

Anyone who uses the same password for their linkedin and company account earned their punishment for intentionally violating their company's information security.
Post reply on HN