Live data from Hacker News

Xkcd: Encryptic

xkcd.com

51–60 of 64 posts

Re: Xkcd: Encryptic

#51
post #6
post #2

Image tooltip text made me laugh: >>It was bound to happen eventually. This data theft will enable almost limitless [xkcd.com/792]-style password reuse attacks in the coming weeks. There's only one group that comes out of this looking smart: Everyone who pirated Photoshop. [xkcd.com/792]: http://xkcd.com/792/

He missed a group of people: any designer who did not entrust their entire professional workflow to a single, for-profit company whose best interests are in moving your workflow in ways that benefit the company over the user. Being dependent on something like Photoshop for your only income is a terrible position to be in, yet it is how I'd describe most designers today.

Of course he missed that it's not funny.

Re: Xkcd: Encryptic

#52
post #22

As funny as this comic is, it wasn't so funny when my card was hacked and my personal details were released online. Now anyone who searches for my email (on Google) is displayed a (spammy) link to the dumped file containing my email, along with some jumbled letters, possibly my encrypted password. One super-good thing I did when I signed up for adobe was: I created a separate email address (purely by co-incidence) th…

> Now anyone who searches for my email (on Google) is displayed a (spammy) link to the dumped file containing my email, along with some jumbled letters, possibly my encrypted password. Hmm. I was one of the hacked users, but googling my email doesn't come up with anything.

It is possible that your file wasn't indexed? The whole dump is 3 point something Gigabytes I think, and in the link only a portion was pasted for obvious size limitations. The indexed file was from a (spammy) copy paste service. so chances are good that the part of file which contained your ID wasn't indexed by google or was deleted. I also sent a complaint to Google and the copy-paste service to take down the file immediately for obvious privacy reasons..

Re: Xkcd: Encryptic

#53

What do the boxes on the right represent? St.peter St.peter St.peter1 password password1 password57 seem to be the first few if I understand correctly.

The favorite of the 12 apostles would be Saint John, not Saint Peter[1] https://en.wikipedia.org/wiki/Disciple_whom_Jesus_loved

That's too many characters, plus "Favourite of 12 Apostles" doesn't mean Jesus', it could be the users. I'm not convinced that it's St. though as when they say name1 that would suggest St. was part of it :p

Re: Xkcd: Encryptic

#54
post #33

What's the status with figuring out the encryption key and breaking all those passwords? Surely there are known passwords. Is there any distributed brute force attempt that I can help with?

1. That's probably illegal so if there was one it wouldn't be publicly advertised

2. If adobe weren't completely stupid (a big if admittedly) it will be infeasible to brute force (>100 bits of entropy)

Re: Xkcd: Encryptic

#55
post #6

Earlier quoted context omitted.

He missed a group of people: any designer who did not entrust their entire professional workflow to a single, for-profit company whose best interests are in moving your workflow in ways that benefit the company over the user. Being dependent on something like Photoshop for your only income is a terrible position to be in, yet it is how I'd describe most designers today.

Not being able to use CMYK is a terrible perspective if you ever get a chance of printing something.

Possibly a kickstarter to code CMYK into gimp would be a good idea? If the gimp team doesn't let you do it, it should be easy enough to fork it with a bit of financial backing from a kickstarter.

Re: Xkcd: Encryptic

#56
post #46
post #22

As funny as this comic is, it wasn't so funny when my card was hacked and my personal details were released online. Now anyone who searches for my email (on Google) is displayed a (spammy) link to the dumped file containing my email, along with some jumbled letters, possibly my encrypted password. One super-good thing I did when I signed up for adobe was: I created a separate email address (purely by co-incidence) th…

Good points, but: >4) Always create a separate email (or an alias) while signing up for cloud services, so you can eliminate guess work during a crisis. So, instead of signing up with example@gmail.com for Adobe or someone else, use example+adobe@gmail.com (this will redirect to example@gmail.com) or rather create adobe.example@gmail.com or something (gmail is just an example). This way, you can always trace out the…

For most it's just easier to use trashmail.net or mailinator.

Re: Xkcd: Encryptic

#57
post #33

What's the status with figuring out the encryption key and breaking all those passwords? Surely there are known passwords. Is there any distributed brute force attempt that I can help with?

1. That's probably illegal so if there was one it wouldn't be publicly advertised 2. If adobe weren't completely stupid (a big if admittedly) it will be infeasible to brute force (>100 bits of entropy)

> it will be infeasible to brute force (>100 bits of entropy)

Really? Even a massively distributed attempt?

Re: Xkcd: Encryptic

#58
post #31
post #25

Earlier quoted context omitted.

"bill@microsoft.com was found. You need to change your passwords now."

example@example.com nospam@nospam.com nospam@here.com Were all found. I feel sorry for the people paying a lot of money to buy these short domain names, and finding huge amounts of spam being delivered to them because people have misused domain names that don't belong to them.

Technically message won't get delivered if it's rejected on SMTP envelope level.

Re: Xkcd: Encryptic

#59
post #46
post #22

As funny as this comic is, it wasn't so funny when my card was hacked and my personal details were released online. Now anyone who searches for my email (on Google) is displayed a (spammy) link to the dumped file containing my email, along with some jumbled letters, possibly my encrypted password. One super-good thing I did when I signed up for adobe was: I created a separate email address (purely by co-incidence) th…

Good points, but: >4) Always create a separate email (or an alias) while signing up for cloud services, so you can eliminate guess work during a crisis. So, instead of signing up with example@gmail.com for Adobe or someone else, use example+adobe@gmail.com (this will redirect to example@gmail.com) or rather create adobe.example@gmail.com or something (gmail is just an example). This way, you can always trace out the…

> Doesn't stop someone just removing the + tag on the email address.

It won't stop spam but the biggest risk with these leaks is from automated testing of a password found from a leak on one service you use with the same email address on another. As long as you use a separate + address for both you'll be safe as they are unlikely to automate testing of different + addresses since most users don't do that.

> A better way is to set up a catch all on a domain... but then you're likely to get a lot more spam

I forward my catch all domain emails to gmail. I hardly get any spam now except to leaked addresses which I've filtered to add bright red labels so I can ignore them.

Re: Xkcd: Encryptic

#60
post #47
post #44

Earlier quoted context omitted.

CMYK is not exclusive to Photoshop, is it?

I guess one of the main competitors to Photoshop is gimp... last time I checked it had bad support for CMYK (see https://wiki.archlinux.org/index.php/CMYK_support_in_The_GIM... )

Gimp is just one free alternative, i guess you knew about its cmyk troubles and posted because of that. Why limit yourself to Gimp though? Check.out other alternatives. I posted some in another comment in this thread.
Post reply on HN