Live data from Hacker News

FBI got Hacked, Reveals Hundreds of Passwords

pastebin.com

31–40 of 100 posts

Re: FBI got Hacked, Reveals Hundreds of Passwords

#31
post #26

joseph.mcqueen@ic.fbi.gov - passwords123 > Joseph McQueen III, chief of the FBI personnel recruitment unit according to [0]. daniel.clegg@ic.fbi.gov - clegg.passwd > is an FBI supervisory agent Some others laura.eimiller@ic.fbi.gov - passwored12 William.So@ic.fbi.gov - cutelilyian191 tammy.mchugh@ic.fbi.gov - passwords123456 Rich.Ernst@osd.mil - ernst.richard celkins@vertizontalinc.com - celkins.vertizon joseph.herol…

I wish you had not done this. I did not want to see anybody's passwords, or create any sort of record that I myself downloaded the password list (which i did not.) Perhaps this is my fault for even clicking on the comments thread of this article. And of course there are many reasons to call me paranoid. Nonetheless, well, I will be moving on now!

Not only did you click on the comments but you created a much more permanent record by posting...maybe you're just trolling?

Re: FBI got Hacked, Reveals Hundreds of Passwords

#32

I don't like this being listed on ycombinator. I have now just gone to a site with all the passwords on, I was expecting an article about it. I do not like the fact that I have just browsed that page!

I agree actually. I have no reason to actually want to see their private information. I do want to know what happened.

Exactly, and that is how it normally is on ycombinator. If there's a link to the actual data on the article, then whoever wants to go to that, go ahead, but I stay away.

Re: FBI got Hacked, Reveals Hundreds of Passwords

#34

I don't like this being listed on ycombinator. I have now just gone to a site with all the passwords on, I was expecting an article about it. I do not like the fact that I have just browsed that page!

Maybe I'm very naive but I have a hard time imagining one would get into trouble by browsing such a list now that it's in the open. Thousands of people are browsing this list right now....

Re: FBI got Hacked, Reveals Hundreds of Passwords

#36

I don't like this being listed on ycombinator. I have now just gone to a site with all the passwords on, I was expecting an article about it. I do not like the fact that I have just browsed that page!

It's linked to a pastebin... should be obvious what's likely to be there.

Re: FBI got Hacked, Reveals Hundreds of Passwords

#38
post #24
post #4

A lot of these are good. Some not so much... passwords123 passwored12 password$qwerty qwertylol@me passwords123456 password123 password111111

What's wrong with 3 and 4? It appears that, in general, the FBI staff are setting reasonable passwords. There are a few passwordNNN types but the majority are adequate and, in my opinion, would hold up well against a brute force vector, which is the primary purpose of password complexity.

The fact that some of those passwords appear very strong also means they weren't bruteforced and therefore most likely stored in plaintext. I guess even the FBI have sloppy programmers...

Re: FBI got Hacked, Reveals Hundreds of Passwords

#39
post #6

All these people with "password123" as their password (and there's a bunch similar to that) should be fired. Sidney MacArthur, you work for the Navy and you have that as a password?

I more so blame the administrator who allowed them to have these passwords (and of course whoever was storing them in plaintext).

The reality is that employees can't be trusted to manage password strength. But it's trivial to implement a validation scheme that forces employees to be over a minimum length, use special characters, etc. Of course this is also not great -- and inevitably we'd see Pa$$word123 -- but it's at least a starting point.

Re: FBI got Hacked, Reveals Hundreds of Passwords

#40
post #36

I don't like this being listed on ycombinator. I have now just gone to a site with all the passwords on, I was expecting an article about it. I do not like the fact that I have just browsed that page!

It's linked to a pastebin... should be obvious what's likely to be there.

I haven't used pastebin...
Post reply on HN