Live data from Hacker News

Ken Thompson's Unix Password

leahneukirchen.org

211–220 of 665 posts

Re: Ken Thompson's Unix Password

#211

Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…

I'm conflicted about this. I know I'd be pretty upset if an employer starting talking to me about a plaintext password that's supposed to be hashed. The problem is that they brute forced it and then sent it directly off to HR? Yes, as a sysadmin it's perfectly acceptable to be searching for weak passwords, but reading the plaintext yourself for fun then scurrying to HR is kinda a slimy thing to do. As an admin you ha…

I wasn't reading the cracked passwords for fun, I was verifying the output. And it was well known that we cracked the passwords, and he had already gotten the first warning that it was cracked, so he knew we knew it.

That's why I didn't feel bad taking it to HR. I already had a sense that he was doing bad stuff, and the password just solidified it for me.

Re: Ken Thompson's Unix Password

#212

Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…

Even if the guy was creepy, you are an asshole revealing something he thought nobody could ever know. That's the same thing like reading his personal letters or similar.

He had already been warned the week before that his password had been cracked, and it was well known that we were cracking passwords.

Re: Ken Thompson's Unix Password

#213

Earlier quoted context omitted.

I'm all for the effective strength enforcement and ejecting the creepy guy, but some people do have strong passwords that, a bad idea though it may be, embed something deeply personal to them. Just something to keep in mind before automating the sharing of cracked passwords for otherwise legitimate purposes. I consider my passwords my private information, even if they are no longer secure from a technical standpoint…

Agreed. I would hope that the first email was automated and nobody actually looked at the results of cracking the passwords. In the second week, you arguably had less expectation of privacy.

Correct, the first warning was automated and the password was not revealed.

Re: Ken Thompson's Unix Password

#214
post #175

Earlier quoted context omitted.

If he was fired for sexual harassment, that is one thing. But a naughty password on its own? That was maybe not the case here but that is what I have doubts about.

What if it was violent, bigoted, or suicidal? Passwords are secret but they aren't necessarily private. If you wouldn't want to verbally verify it with your administrator you probably shouldn't use it.

I have seen many password policies that says that you never should disclose your password. I have never seen a password policy say that it must not be naughty. As for violent or suicidal, I am less sure. I guess I would reason like a doctor, who has a patient's privacy to consider, but when certain lines are crossed he can contact the police if he think there is risk of crime.

Re: Ken Thompson's Unix Password

#215

Earlier quoted context omitted.

I'm all for the effective strength enforcement and ejecting the creepy guy, but some people do have strong passwords that, a bad idea though it may be, embed something deeply personal to them. Just something to keep in mind before automating the sharing of cracked passwords for otherwise legitimate purposes. I consider my passwords my private information, even if they are no longer secure from a technical standpoint…

I wonder if that process was passed by legal first. Not only does it make private (in most user's minds) information public, it also makes it legally discoverable!

Yes, it was passed by legal and everyone else. The first warning was automated and the password wasn't revealed. It was only on the second pass once you had ample warning.

But to be fair, I wouldn't do that today. I would just shut off the account on the second pass.

Re: Ken Thompson's Unix Password

#218
post #196

Earlier quoted context omitted.

I think it's very interesting how, despite knowing nearly nothing about the situation, everyone here is quick to doubt the victim, and make up scenarios (for which there is zero evidence) where the harasser is the victim.

For all its flaws, innocent until proven guilty is still the fairest justice system. Beyond a reasonable doubt is a high standard of proof. Because we use this standard, it is natural for people to look for reasonable doubts when talking about accusations. That is how western society works. And for very good reasons.

> innocent until proven guilty is still the fairest justice system

Justice system administered by a state where the repercussions include imprisonment and death - absolutely. But HR is not a judicial system and should not be viewed as one. I think I take your point to be just a descriptive observation of "our social discussion reflects a habit based on our exposure to judicial systems" and not a normative statement. Even if it's the former, I think it's naive and ignores a very real culture of doubt and victim-blaming exclusive to sexual violence.

Re: Ken Thompson's Unix Password

#219
post #196

Earlier quoted context omitted.

I think it's very interesting how, despite knowing nearly nothing about the situation, everyone here is quick to doubt the victim, and make up scenarios (for which there is zero evidence) where the harasser is the victim.

For all its flaws, innocent until proven guilty is still the fairest justice system. Beyond a reasonable doubt is a high standard of proof. Because we use this standard, it is natural for people to look for reasonable doubts when talking about accusations. That is how western society works. And for very good reasons.

It's how the courts work, but not society in general. An individual can use whatever standard they wish to form an opinion. Would you insist that we all treat O.J. Simpson as innocent?

Re: Ken Thompson's Unix Password

#220

Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…

I'm conflicted about this. I know I'd be pretty upset if an employer starting talking to me about a plaintext password that's supposed to be hashed. The problem is that they brute forced it and then sent it directly off to HR? Yes, as a sysadmin it's perfectly acceptable to be searching for weak passwords, but reading the plaintext yourself for fun then scurrying to HR is kinda a slimy thing to do. As an admin you ha…

Yeah that is some NSA shit.
Post reply on HN