Live data from Hacker News

I Am Releasing Ten Million Passwords

xato.net

31–40 of 229 posts

Re: I Am Releasing Ten Million Passwords

#31
This is great, but if you use a password manager, it's very difficult to determine which, if any, of your accounts would be compromised. For myself, this would just be doing a dump and looping a few greps. But for family and friends, does anyone have any ideas for a less technical audience?

Re: I Am Releasing Ten Million Passwords

#32

I don't understand exactly why it's necessary to release usernames along with the passwords, or why it's ethical to do so. Stripping the domain portion of email addresses does absolutely nothing when you can find the real email, and other accounts of the victim, by Googling the unique part of the email address. How does tying each password to its corresponding username help with password research, and does the value…

Probably to find out how many people do stuff like type their username backwards as a password/what kind of patterns they use. If that is useful enough information to warrant publishing data like this is debatable, yes.

Re: I Am Releasing Ten Million Passwords

#34

When I first got on the Internet in 1994 I used the same password for everything for the next decade before I became security conscious (now I have a random, strong, unique password for every service). Anyways, that password is not in this list. I have found it in other password dumps before. So, I don't know what to think.

This isn't a comprehensive list of all leaked passwords. It's a random subset of 10 million for research purposes.

Re: I Am Releasing Ten Million Passwords

#35
I could be relieved that my favourite password isn't in there but it's already been leaked by stupid, stupid engineers working for Riot (League of Legends video game) who stored it in plaintext and a hacker got it. It is a good practice to regularly change passwords anyways: If you're worried that your password is in there, you're doing it wrong in the first place.

Re: I Am Releasing Ten Million Passwords

#38
post #30

When I first got on the Internet in 1994 I used the same password for everything for the next decade before I became security conscious (now I have a random, strong, unique password for every service). Anyways, that password is not in this list. I have found it in other password dumps before. So, I don't know what to think.

I don't think it is necessary to have one password for every single system, but three or fours tiers of passwords. And just keep in mind that there's one password to "rule them all". That is the password for the primary mail account. I use 2-factor authentication for that.

> three or fours tiers of passwords

Can you elaborate? My first thought is tiered by category of the service. No, I don't want my financial institutions to all have the same password, even if it's from the most secure tier.

Re: I Am Releasing Ten Million Passwords

#39

I don't understand exactly why it's necessary to release usernames along with the passwords, or why it's ethical to do so. Stripping the domain portion of email addresses does absolutely nothing when you can find the real email, and other accounts of the victim, by Googling the unique part of the email address. How does tying each password to its corresponding username help with password research, and does the value…

A list of 10 million passwords alone answers almost no questions. In fact, it's probably possible to programmatically predict, with a depressing level of accuracy, what a great deal of such a list will look like, given the already available research about the distribution of complexity, the parts of speech and numbers commonly used and in what patterns, etc.

So, the next interesting question is: given the already plaintext-available lists of usernames and passwords, just how much coverage is there in the known space? Are your passwords known? Are your users' and clients' passwords known?

This document is perfect for a true positive on the matter of needing to deprecate particular combinations of username and password, and, as an obvious corollary, presenting evidence for consultation advice about the same. (Of course, being only a sample, it doesn't say anything about a true negative.)

Post reply on HN