i've seen people using them, and if i were of a less honourable persuasion i could abuse that quite easily... on the other hand, its impossible for me to steal information from out of their brain (so far at least).
Hack of Cupid Media dating website exposes 42 million plaintext passwords
61–70 of 168 posts
Re: Hack of Cupid Media dating website exposes 42 million plaintext passwords
#62Earlier quoted context omitted.
"The answer" doesn't exist and it never will. Everyone has to do their part. Services that store passwords in plaintext should definitely be publicly shamed, every single time.
The problem is that "publicly shamed" means "shamed amongst security geeks". Most websites main demographic is not security geeks.
I think even the most non-tech people would react to such a news story.
Re: Hack of Cupid Media dating website exposes 42 million plaintext passwords
#63Earlier quoted context omitted.
Free markets currently doing a pretty awful job of it as we keep learning. Perhaps some government legislation would help.
You can't legislate away stupid behavior. There will always be an endless parade of poor choices. If it's not 'this,' it's 'that' and then the next 'thing.' There is no scenario under which a government entity can enforce, keep up with, or properly control such.
There needs to be a strong deterrent.
Re: Hack of Cupid Media dating website exposes 42 million plaintext passwords
#64Earlier quoted context omitted.
Installing lastpass on every machine I happen to stroll by and want to use isn't the cleanest of solutions... and I shouldn't have to trust my keys to one closed, proprietary application. With a standard protocol at least I'd have a choice about my client. There are also peripheral issues with password databases, like the fact that they make the mere fact that you're using one transparent to anyone investigating your…
You can ofcourse log in to lastpass.com on any other machine you are sure doesn't have a keylogger (well they provide virtual keyboard also if thats the case). But ofcourse, that's matter of trust, even when they say that data is encrypted client side and they store only blob of gibberish. However I feel so relieved by using LastPass - not having to worry about remembering yet another password.
And one solution, whether it's backdoored or not, is still one target for bad actors to focus on (viruses, spoofing, etc).
Re: Hack of Cupid Media dating website exposes 42 million plaintext passwords
#65Just a random question: Is there anything that gives companies incentive to prevent such hacks? It seems that there is no consequences at all, except for some loss of reputation in tech community. Is there a way to put legal pressure on tightening up security?
Re: Hack of Cupid Media dating website exposes 42 million plaintext passwords
#66maybe i am just stupid, but how are password managers secure? i've seen people using them, and if i were of a less honourable persuasion i could abuse that quite easily... on the other hand, its impossible for me to steal information from out of their brain (so far at least).
It's easier than you think to steal passwords from people. Just ask for it!
http://www.veracode.com/blog/2013/03/hacking-the-mind-how-wh...
Re: Hack of Cupid Media dating website exposes 42 million plaintext passwords
#67maybe i am just stupid, but how are password managers secure? i've seen people using them, and if i were of a less honourable persuasion i could abuse that quite easily... on the other hand, its impossible for me to steal information from out of their brain (so far at least).
Re: Hack of Cupid Media dating website exposes 42 million plaintext passwords
#68Before the bcryot/scrypt advocacy and general shaming starts... I'll just make the same comment I always do when this happens: the answer is not more sever side hashing. Trusting remote services with plaintext passwords is broken to begin with. We shouldn't give them the chance to mess this up. We need client side hashing and key-stretching that only something like SRP can provide: https://en.wikipedia.org/wiki/Secur…
This is an is/ought fallacy. As professionals we don't get to propose the ideal universe as the solution to the problems of the actual universe. We have to take what we can get right now.
It's not beyond the realm of possibility that browsers might be updated to support some form of Secure Remote Protocol standard. And to encourage web sites to use it browsers could display a little 'padlock' icon similar to the HTTPS icon.
Re: Hack of Cupid Media dating website exposes 42 million plaintext passwords
#69Earlier quoted context omitted.
Yes, the government would surely do a great job legislating development standards. Just look how terrifically they've handled software patents.
Free markets currently doing a pretty awful job of it as we keep learning. Perhaps some government legislation would help.
Get the government involved and it won't be long before you need to fill out 15 forms and hire a lawyer to put your weekend project online. Is that the kind of internet you want?
Re: Hack of Cupid Media dating website exposes 42 million plaintext passwords
#70Earlier quoted context omitted.
The problem is that "publicly shamed" means "shamed amongst security geeks". Most websites main demographic is not security geeks.
Not necessarily. If a relatively mainstream news site reported the event and quoted a security professional saying: "Website X didn't even try to keep your love life and dating profile a secret. Every single user's password is now publicly available. If you use the same password on multiple sites, be sure to change it quickly!" I think even the most non-tech people would react to such a news story.