Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

211–220 of 292 posts

Re: Notes on the Celebrity Data Theft

#211
post #4

Earlier quoted context omitted.

>Dude. 1Password. Password managers only protect against certain kinds of attack. Many cloud services do not or can not properly encrypt their users' data, so having a strong password won't help in the event that your cloud provider's datacenter gets rooted.

You can't, but if you use a password manager, you can actually use different passwords on every service. And you can use stronger passwords (if the service permits), thus if they only lost the passwords datbased (assuming it's hashed) you are still safe.

No because say your cloud provider recycle your hard drive to another client with a bad password, then the attacker not only can access the data of the other client but can run a file recovery tool and get some of your files.

Most providers don't erase disks properly. Takes too much time.

Re: Notes on the Celebrity Data Theft

#212
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

I started using Mitro , recently for the same thing. I had been slowly working on a system which would store pseudo-randomly generated salts and store one for each individual domain. It would detect which site I was entering my password into, take the relevant salt and digest it against the password I had entered - sending a stupidly long, digested passwords to the sites which would allow for it. The password itself…

> I had been slowly working on a system...

If you're still interested in this type of system, PasswordMaker has been around for quite a while and does essentially the same thing:

http://www.passwordmaker.org/

Re: Notes on the Celebrity Data Theft

#213

Earlier quoted context omitted.

Well the fact that JenLaw's photos went for the extremely huge amount of $130 suggests that either there's a lot more of it out there, or that the guy who stole them couldn't fence them (per [0] thread). Anyway, you summed up the take-away from the article perfectly. Since this seems to be going on for some time, I wonder how the whole ecosystem kept coordinating this well so far, that it's the first time we hear abo…

Yeah, there's some hard-to-accept math in that story. If JenLaw's photos were worth $130 or so, that means that any photos that any of us have are associated with a market value. And it ain't that much.

That sounds about right. There are a lot of photos out there, so the individual value is small.

Re: Notes on the Celebrity Data Theft

#214
post #95

Earlier quoted context omitted.

Don't use an "idiot" password, use a long password.. Good passwords aren't complex, they're LONG.. "this is a really dumb password" is probably actually a really good password. ;-) And also, your "problem" is simply your decision to trade security for convenience. You need to weigh the risks vs. reward and make the choice for yourself. If something goes wrong, at least you'll know why.

Long passwords (aka the xkcd scheme) aren't secure anymore - https://www.schneier.com/blog/archives/2014/03/choosing_secu... The only good passwords are ones that stay well away from dictionary words..

Bruce Schneier clearly misunderstood the xkcd scheme.

In fact, the Schneier method for generating passwords is probably worse than the xkcd method because a significant percentage of the people who try to use his method will choose a password with low entropy such as "wtpotusio2fampu" (We The People of he United States...) or "igmhaohcr" (I'm gonna make him an offer he can't refuse).

All I have to do is crawl the internet and calculate, say, the top 5 million n-grams. The resulting 5 million candidate passwords would be far more likely to match a typical Schneier-based password than a corresponding list of 5 million candidate passwords designed to match an xkcd-based password.

The simple rule is this: Don't let users choose a password. They suck at it.

Re: Notes on the Celebrity Data Theft

#215
post #211

Earlier quoted context omitted.

You can't, but if you use a password manager, you can actually use different passwords on every service. And you can use stronger passwords (if the service permits), thus if they only lost the passwords datbased (assuming it's hashed) you are still safe.

No because say your cloud provider recycle your hard drive to another client with a bad password, then the attacker not only can access the data of the other client but can run a file recovery tool and get some of your files. Most providers don't erase disks properly. Takes too much time.

Don't use Password managers because someone can always root a server and unerase deleted files.

Logic. Win.

Re: Notes on the Celebrity Data Theft

#216

Earlier quoted context omitted.

It's a pain, but really not that bad. You tweet from your phone (or use email/SMS/whatever else). 20 characters is manageable and secure, as long as it's randomly generated.

If it's randomly generated, it's impossible to remember to fill in on your phone. Unless you have it on a piece of paper in your wallet.

[deleted]

Re: Notes on the Celebrity Data Theft

#217

The thing that bugs me is that you could have good password practices. But if you're having a party, having a fun time (and lets face it, people are going to do shit...), and one of your friends is snapping photos of you, and they have bad password practices, then you are kind of screwed. People don't typically make friends on the basis of: do you have good password practices.

Or: you've got good password practices, but you send content to someone who doesn't. Or they do. Or their friends do ...

When you realize that celebrity nudes are only the tip ("just the tip") of this iceberg, the real implications start sinking in.

The groups trading in info were also targeting exes and other associates, possibly businesspeople, politicians, and others, and the information in question isn't merely skin pics but _anything_ that was on those accounts.

Re: Notes on the Celebrity Data Theft

#218

Earlier quoted context omitted.

Long passwords (aka the xkcd scheme) aren't secure anymore - https://www.schneier.com/blog/archives/2014/03/choosing_secu... The only good passwords are ones that stay well away from dictionary words..

The Schneier article is puzzling; the security of the diceware/XKCD scheme doesn't rely on the word list being secret, just on the words from the list being chosen randomly. 4 words randomly chosen from a list of 5000 provide about 49 bits of entropy when the list of words is fully known . Against an attacker who knows exactly how you chose your password, it's (roughly) the same level of security as a 14-digit numeri…

His point is that using actual, grammatically correct, sentences is not the same as using several random words. As your mobile keyboard autocomplete well knows, after a certain word there are words more probable than others.

How many people use this kind of approach, I don't know. Schneier seems to focus on "three random letters" kind of attacker.

Re: Notes on the Celebrity Data Theft

#219
post #113

Earlier quoted context omitted.

I don't get Apple's password based security at all. The stupid question/answer thing they forced everyone to do was just crazy. You have a physical device in your possession. Apple don't seem to have heard about two factor auth. If the only company on the planet that obsessively ties consumer hardware and software into a single cohesive product can't get their shit together the future worries me. It should be the def…

They've had two-step authentication since March of 2013: http://support.apple.com/kb/ht5570

Except the article seems to be saying that Apple's two-factor auth isn't required to access iCloud backups and that it only protects account details, payment methods, etc.

Re: Notes on the Celebrity Data Theft

#220
post #168
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

I've been using a scheme that involve easy to type password, like: qwertyuioplkjhgfdsa/ qazcdetgbmju / rtyujhgfvbnm (if you 're wondering how to memorize those password, looks at the QWERTY keyboard). Combining with number and capitalization, I feel pretty good about my odd of surviving the brute force/ dictionary attack. But I can't quite quality the exact amount of combinations for those schemes. Can anyone tell me…

You should look at some wordlists. A lot of qwerty / qazwsx / asdf combinations appear.
Post reply on HN