Live data from Hacker News

I Am Releasing Ten Million Passwords

xato.net

21–30 of 229 posts

Re: I Am Releasing Ten Million Passwords

#21

Everyone knows the whole email/password concept is broken. I believe that overall OAUTH is needed, but it needs a much stronger consumer facing view.

I'm not sure how OAuth can help. Does it allow you to choose whom to authenticate with, or does it tie you to one specific provider? I much prefer Persona, but Mozilla has abandoned it, and most resources around it are dead links. What a colossal shame.

I'm personally looking forward to something like SQRL.

https://www.grc.com/sqrl/sqrl.htm

Re: I Am Releasing Ten Million Passwords

#22
post #17
post #3

Barrett Brown was not convicted merely for linking to data on the web. He was convicted for three separate offenses: 1. Acting as a go-between for (presumably Jeremy Hammond) the Stratfor hacker and Stratfor itself, Brown misled Stratfor in order to throw the scent off Hammond. Having intimate knowledge of a crime doesn't make one automatically liable for that crime, but does put them in a precarious legal position i…

The trafficking charges were dropped but he still was charged as an accessory after the fact. http://cryptome.org/2015/01/brown-105.pdf

Yes; that's #1 in my list. Thanks for the link to the sentencing memo!

Re: I Am Releasing Ten Million Passwords

#24

Earlier quoted context omitted.

I'm not sure how OAuth can help. Does it allow you to choose whom to authenticate with, or does it tie you to one specific provider? I much prefer Persona, but Mozilla has abandoned it, and most resources around it are dead links. What a colossal shame.

I'm personally looking forward to something like SQRL. https://www.grc.com/sqrl/sqrl.htm

That's also a nice protocol, but I think it requires too many extra things (mobile phone, net connection, etc). Plus, what if your key gets stolen?

Re: I Am Releasing Ten Million Passwords

#25
post #3

Barrett Brown was not convicted merely for linking to data on the web. He was convicted for three separate offenses: 1. Acting as a go-between for (presumably Jeremy Hammond) the Stratfor hacker and Stratfor itself, Brown misled Stratfor in order to throw the scent off Hammond. Having intimate knowledge of a crime doesn't make one automatically liable for that crime, but does put them in a precarious legal position i…

> Barrett Brown was not convicted merely for linking to data on the web. From the article: Most of us expected that those charges would be dropped and some were, although they still influenced his sentence. I want to be generous and say that the author meant what you said. The linking was not something Brown was charged with, but it was brought up during the sentencing and probably influenced the length of his prison…

I'm not seeing where the linking was used to enhance his accessory conviction. Is there a source for that?

Re: I Am Releasing Ten Million Passwords

#26
When I first got on the Internet in 1994 I used the same password for everything for the next decade before I became security conscious (now I have a random, strong, unique password for every service).

Anyways, that password is not in this list. I have found it in other password dumps before. So, I don't know what to think.

Re: I Am Releasing Ten Million Passwords

#27
I don't understand exactly why it's necessary to release usernames along with the passwords, or why it's ethical to do so. Stripping the domain portion of email addresses does absolutely nothing when you can find the real email, and other accounts of the victim, by Googling the unique part of the email address.

How does tying each password to its corresponding username help with password research, and does the value gained outweigh the cost of someone using this list for malicious purposes?

I'm not saying this should be illegal, but I'm struggling to understand the intent here.

Re: I Am Releasing Ten Million Passwords

#28
Forgive me for doing so, but allow me to ask some possibly ignorant questions and perhaps play the devil's advocate for a moment. What about this release will help? What are the compelling research problems in the space?

We know users pick bad passwords. It seems to me the most compelling "problem" is hardly a research question -- isn't it about finding ways to encourage users pick strong passwords, not share them between sites, and not put them on sticky notes on their monitors.

Ok, putting my charitable hat again... My best guess is that researchers would like some idea about how long it takes to crack some percentage of accounts; e.g. with rainbow tables or other techniques?

The author mentioned "Analysis of usernames with passwords is an area that has been greatly neglected and can provide as much insight as studying passwords alone." What directions might a researcher take this?

Re: I Am Releasing Ten Million Passwords

#30

When I first got on the Internet in 1994 I used the same password for everything for the next decade before I became security conscious (now I have a random, strong, unique password for every service). Anyways, that password is not in this list. I have found it in other password dumps before. So, I don't know what to think.

I don't think it is necessary to have one password for every single system, but three or fours tiers of passwords.

And just keep in mind that there's one password to "rule them all". That is the password for the primary mail account. I use 2-factor authentication for that.

Post reply on HN