Live data from Hacker News

FBI got Hacked, Reveals Hundreds of Passwords

pastebin.com

41–50 of 100 posts

Re: FBI got Hacked, Reveals Hundreds of Passwords

#41
post #34

I don't like this being listed on ycombinator. I have now just gone to a site with all the passwords on, I was expecting an article about it. I do not like the fact that I have just browsed that page!

Maybe I'm very naive but I have a hard time imagining one would get into trouble by browsing such a list now that it's in the open. Thousands of people are browsing this list right now....

It's half principle and I think that I would worry about things like that. I have no idea what kind of monitoring tools and methods the FBI have and I don't want any attention because someone linked a load of passwords to ycombinator and I went to it expecting a fairly inocent article :)

Re: FBI got Hacked, Reveals Hundreds of Passwords

#42
post #6

All these people with "password123" as their password (and there's a bunch similar to that) should be fired. Sidney MacArthur, you work for the Navy and you have that as a password?

fired? seriously?

I don't know if i agree with fired but if you work for the fbi, you probably have some access to non-public information, some people have classified or high clearance levels. If you can't manage to have a password that matches patterns that people warn you to avoid for your facebook let alone your fbi password maybe your supervisor should reevaluate what level of trust you should be given

Re: FBI got Hacked, Reveals Hundreds of Passwords

#43

I don't like this being listed on ycombinator. I have now just gone to a site with all the passwords on, I was expecting an article about it. I do not like the fact that I have just browsed that page!

This is Hacker News...I appreciate the direct source of the leak. Not some shitty article that someone wrote about what happened. If you don't like it, don't click it.

Re: FBI got Hacked, Reveals Hundreds of Passwords

#44

This is what you get for encouraging just one type of password strength (i.e. character set) while almost ignoring another (i.e. length). For example I bet this wouldn't pass the FBI's requirements: - Clowns with clown makeup But this would: - password123

haha, this is the best password.

Re: FBI got Hacked, Reveals Hundreds of Passwords

#45
post #38
post #24

Earlier quoted context omitted.

What's wrong with 3 and 4? It appears that, in general, the FBI staff are setting reasonable passwords. There are a few passwordNNN types but the majority are adequate and, in my opinion, would hold up well against a brute force vector, which is the primary purpose of password complexity.

The fact that some of those passwords appear very strong also means they weren't bruteforced and therefore most likely stored in plaintext. I guess even the FBI have sloppy programmers...

They say on the pastebin that one connexion sent passwords in clear text (through asipx-webadmin), so they probably were read there. At least it was probably an entry point.

Re: FBI got Hacked, Reveals Hundreds of Passwords

#47
I'm sure this comment will be heavily downvoted but I read several times that FBI and similar agencies were 7 years ahead in terms of technology including security of systems.

I didn't believe in those quotes and every time a situation like this happens I'm more convinced that they are no more advanced than the big companies (Microsoft, Mozilla...) and depend heavily on the updates released by those companies every week... Just my 5 cents...

Re: FBI got Hacked, Reveals Hundreds of Passwords

#48
post #29

This is what you get for encouraging just one type of password strength (i.e. character set) while almost ignoring another (i.e. length). For example I bet this wouldn't pass the FBI's requirements: - Clowns with clown makeup But this would: - password123

Why do you think there were such requirements? Amongs the passwords I see: marklevett, looskwoooish or even qwertylolqwerty. Browsing the list the only think I could think they enforced was a minimum character count. I see no whitespace or underscores either. So I guess Clowns.with.clown.makeup would've worked. Anyway, the real issue is: why were those passwords stored as plaintext?

Maybe they weren't stored in plaintext, they could have been reversed from the hash. A lot of legacy systems still store passwords in something like 3DES which is trivial to reverse.

PS - "reverse" just means using either rainbow tables or generating the entire set for a given hash(n).

Re: FBI got Hacked, Reveals Hundreds of Passwords

#50

I'm sure this comment will be heavily downvoted but I read several times that FBI and similar agencies were 7 years ahead in terms of technology including security of systems. I didn't believe in those quotes and every time a situation like this happens I'm more convinced that they are no more advanced than the big companies (Microsoft, Mozilla...) and depend heavily on the updates released by those companies every w…

Just the statement that one's organization is "seven years ahead in terms of computer security" implies a fair amount of technological ignorance.

How can an organization be seven years ahead of everyone else? Do they have Norton Antivirus 17.0, whereas the rest of us are using 10.0?

Post reply on HN