I Am Releasing Ten Million Passwords
31–40 of 229 posts
Re: I Am Releasing Ten Million Passwords
#32I don't understand exactly why it's necessary to release usernames along with the passwords, or why it's ethical to do so. Stripping the domain portion of email addresses does absolutely nothing when you can find the real email, and other accounts of the victim, by Googling the unique part of the email address. How does tying each password to its corresponding username help with password research, and does the value…
Re: I Am Releasing Ten Million Passwords
#33Re: I Am Releasing Ten Million Passwords
#34When I first got on the Internet in 1994 I used the same password for everything for the next decade before I became security conscious (now I have a random, strong, unique password for every service). Anyways, that password is not in this list. I have found it in other password dumps before. So, I don't know what to think.
Re: I Am Releasing Ten Million Passwords
#35Re: I Am Releasing Ten Million Passwords
#36For the lazy: grep -i 10-million-combos.txt
Re: I Am Releasing Ten Million Passwords
#37For the lazy: grep -i 10-million-combos.txt
Re: I Am Releasing Ten Million Passwords
#38When I first got on the Internet in 1994 I used the same password for everything for the next decade before I became security conscious (now I have a random, strong, unique password for every service). Anyways, that password is not in this list. I have found it in other password dumps before. So, I don't know what to think.
I don't think it is necessary to have one password for every single system, but three or fours tiers of passwords. And just keep in mind that there's one password to "rule them all". That is the password for the primary mail account. I use 2-factor authentication for that.
Can you elaborate? My first thought is tiered by category of the service. No, I don't want my financial institutions to all have the same password, even if it's from the most secure tier.
Re: I Am Releasing Ten Million Passwords
#39I don't understand exactly why it's necessary to release usernames along with the passwords, or why it's ethical to do so. Stripping the domain portion of email addresses does absolutely nothing when you can find the real email, and other accounts of the victim, by Googling the unique part of the email address. How does tying each password to its corresponding username help with password research, and does the value…
So, the next interesting question is: given the already plaintext-available lists of usernames and passwords, just how much coverage is there in the known space? Are your passwords known? Are your users' and clients' passwords known?
This document is perfect for a true positive on the matter of needing to deprecate particular combinations of username and password, and, as an obvious corollary, presenting evidence for consultation advice about the same. (Of course, being only a sample, it doesn't say anything about a true negative.)