Adobe credentials and the serious insecurity of password hints
1–10 of 43 posts
Re: Adobe credentials and the serious insecurity of password hints
#2I know I know, I just shouldn't use Ghostery but I like to have a little privacy online.
Sorry I won't return to your site again...
Re: Adobe credentials and the serious insecurity of password hints
#3Re: Adobe credentials and the serious insecurity of password hints
#4Re: Adobe credentials and the serious insecurity of password hints
#5I got Ghostery installed, the page loads and then suddenly the text of the article is removed. I know I know, I just shouldn't use Ghostery but I like to have a little privacy online. Sorry I won't return to your site again...
Re: Adobe credentials and the serious insecurity of password hints
#6Troy wondered if there might be a security risk to announcing having found these matches (I suppose the reasoning is that if passwords are reused once, they are probably reused more than once, and so looking for such notices might help crackers track down easily compromised accounts), but decides there is not. Given the low-key way FB have gone about this, I guess this is right, and maybe this should be best practice for future password leaks. I wonder if anyone else has done this?
For convenience, the announcement by Chris Long, of FB (from his comment on Brian Krebs' blog, at http://krebsonsecurity.com/2013/11/facebook-warns-users-afte...):
> I work at Facebook on the security team that helped protect the accounts affected by the Adobe breach. Brian’s comment above is essentially spot on. We used the plaintext passwords that had already been worked out by researchers. We took those recovered plaintext passwords and ran them through the same code that we use to check your password at login time.
> Like Brian’s story indicates, we’re proactive about finding sources of compromised passwords on the Internet. Through practice, we’ve become more efficient and effective at protecting accounts with credentials that have been leaked, and we use an automated process for securing those accounts.
Re: Adobe credentials and the serious insecurity of password hints
#7I got Ghostery installed, the page loads and then suddenly the text of the article is removed. I know I know, I just shouldn't use Ghostery but I like to have a little privacy online. Sorry I won't return to your site again...
Try disconnect.me or blacklisting the sites directly from the hosts file.
Re: Adobe credentials and the serious insecurity of password hints
#8I got Ghostery installed, the page loads and then suddenly the text of the article is removed. I know I know, I just shouldn't use Ghostery but I like to have a little privacy online. Sorry I won't return to your site again...
Re: Adobe credentials and the serious insecurity of password hints
#9Use case is to implement the FB-style security escalation for high-value accounts at my businesses, without requiring an on-call security team. If a dentist loses their client database because they reused the password on a PHPBB somewhere I'm likely in for a lot of headaches even if eventually found to not be at fault.
Re: Adobe credentials and the serious insecurity of password hints
#10I got Ghostery installed, the page loads and then suddenly the text of the article is removed. I know I know, I just shouldn't use Ghostery but I like to have a little privacy online. Sorry I won't return to your site again...
Don't use Ghostery because they're tracking you: http://en.wikipedia.org/wiki/Ghostery#Criticism Try disconnect.me or blacklisting the sites directly from the hosts file.
Thanks for disconnect.me, I'll give it a shot :)