Live data from Hacker News

Adobe credentials and the serious insecurity of password hints

troyhunt.com

1–10 of 43 posts

Re: Adobe credentials and the serious insecurity of password hints

#5
post #2

I got Ghostery installed, the page loads and then suddenly the text of the article is removed. I know I know, I just shouldn't use Ghostery but I like to have a little privacy online. Sorry I won't return to your site again...

It's a stupid interaction with Disqus. I don't think it's the site's (troyhunt.com) fault because the text of the article is all in the original HTML of the page. It is Ghostery and the way it blocks Disqus that causes the article to vanish.

Re: Adobe credentials and the serious insecurity of password hints

#6
It was smart of Facebook to look for reused passwords.

Troy wondered if there might be a security risk to announcing having found these matches (I suppose the reasoning is that if passwords are reused once, they are probably reused more than once, and so looking for such notices might help crackers track down easily compromised accounts), but decides there is not. Given the low-key way FB have gone about this, I guess this is right, and maybe this should be best practice for future password leaks. I wonder if anyone else has done this?

For convenience, the announcement by Chris Long, of FB (from his comment on Brian Krebs' blog, at http://krebsonsecurity.com/2013/11/facebook-warns-users-afte...):

> I work at Facebook on the security team that helped protect the accounts affected by the Adobe breach. Brian’s comment above is essentially spot on. We used the plaintext passwords that had already been worked out by researchers. We took those recovered plaintext passwords and ran them through the same code that we use to check your password at login time.

> Like Brian’s story indicates, we’re proactive about finding sources of compromised passwords on the Internet. Through practice, we’ve become more efficient and effective at protecting accounts with credentials that have been leaked, and we use an automated process for securing those accounts.

Re: Adobe credentials and the serious insecurity of password hints

#7
post #2

I got Ghostery installed, the page loads and then suddenly the text of the article is removed. I know I know, I just shouldn't use Ghostery but I like to have a little privacy online. Sorry I won't return to your site again...

Don't use Ghostery because they're tracking you: http://en.wikipedia.org/wiki/Ghostery#Criticism

Try disconnect.me or blacklisting the sites directly from the hosts file.

Re: Adobe credentials and the serious insecurity of password hints

#8
post #2

I got Ghostery installed, the page loads and then suddenly the text of the article is removed. I know I know, I just shouldn't use Ghostery but I like to have a little privacy online. Sorry I won't return to your site again...

Hey, thanks for pointing that out, that's the second time I've heard that recently. I think Ghoetery is getting a little over-excited and hiding the parent element containing Disqus which also contains the body of the post. I'm going to take a look at how to rejig the markup so that this doesn't happen in future.

Re: Adobe credentials and the serious insecurity of password hints

#9
I don't have the resources of a Facebook, but I'd pay a few hundred bucks a year for a HTTPS secured REST API which let me post an email address and receive a list of candidate passwords. Bonus for a callback if someone I've queried gets added. The service would maintain that list in a fashion similar to whitehat security researchers.

Use case is to implement the FB-style security escalation for high-value accounts at my businesses, without requiring an on-call security team. If a dentist loses their client database because they reused the password on a PHPBB somewhere I'm likely in for a lot of headaches even if eventually found to not be at fault.

Re: Adobe credentials and the serious insecurity of password hints

#10
post #7
post #2

I got Ghostery installed, the page loads and then suddenly the text of the article is removed. I know I know, I just shouldn't use Ghostery but I like to have a little privacy online. Sorry I won't return to your site again...

Don't use Ghostery because they're tracking you: http://en.wikipedia.org/wiki/Ghostery#Criticism Try disconnect.me or blacklisting the sites directly from the hosts file.

I kept using ghostery because I didn't know of any alternative and sometimes I can't install adsuck. (which is is better than a huge hosts file. An oversized hosts file can have a negative impact on DNS and overall network responsiveness).

Thanks for disconnect.me, I'll give it a shot :)

Post reply on HN