Live data from Hacker News

Ken Thompson's Unix Password

leahneukirchen.org

301–310 of 665 posts

Re: Ken Thompson's Unix Password

#301

Earlier quoted context omitted.

I'm conflicted about this. I know I'd be pretty upset if an employer starting talking to me about a plaintext password that's supposed to be hashed. The problem is that they brute forced it and then sent it directly off to HR? Yes, as a sysadmin it's perfectly acceptable to be searching for weak passwords, but reading the plaintext yourself for fun then scurrying to HR is kinda a slimy thing to do. As an admin you ha…

Yes, creepy sexists need our protection and it's exactly the same thing as playing farmville on the bathroom.

"Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith."

"Don't be snarky."

https://news.ycombinator.com/newsguidelines.html

Re: Ken Thompson's Unix Password

#302

Earlier quoted context omitted.

Yes, creepy sexists need our protection and it's exactly the same thing as playing farmville on the bathroom.

Cool, false equivalence seems to be the norm on HN nowadays

Please don't reply to a bad comment with another bad comment. That only makes this place even worse.

https://news.ycombinator.com/newsguidelines.html

Re: Ken Thompson's Unix Password

#304

Earlier quoted context omitted.

I'm conflicted about this. I know I'd be pretty upset if an employer starting talking to me about a plaintext password that's supposed to be hashed. The problem is that they brute forced it and then sent it directly off to HR? Yes, as a sysadmin it's perfectly acceptable to be searching for weak passwords, but reading the plaintext yourself for fun then scurrying to HR is kinda a slimy thing to do. As an admin you ha…

Yes, creepy sexists need our protection and it's exactly the same thing as playing farmville on the bathroom.

Yep you got it right.

Re: Ken Thompson's Unix Password

#305

Earlier quoted context omitted.

Yeah that is some NSA shit.

Not really. It was well known that passwords were being cracked, and the guy in question was even warned already that his password had been cracked the week before.

Much "NSA shit" is also well known.

The questionable behavior in this case is getting a guy fired for selecting a politically-incorrect secret passphrase. This is merely one step removed from reading his brain and figuring out he fantasizes about spanking coworkers while having sex with them. (I've done this, and yet we are good friends!)

We don't know all the details, maybe that guy actually harassed people, but scrutinizing someone's private thoughts without prior suspicion for offensive-but-noncriminal behavior that can be pivoted into larger accusations is how police states work.

In the best case, this encourages people to filter their private thoughts and actions by the standards of what is acceptable to advertise publicly, which is incredibly unhealthy and oppressive.

Re: Ken Thompson's Unix Password

#306

Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…

I'm conflicted about this. I know I'd be pretty upset if an employer starting talking to me about a plaintext password that's supposed to be hashed. The problem is that they brute forced it and then sent it directly off to HR? Yes, as a sysadmin it's perfectly acceptable to be searching for weak passwords, but reading the plaintext yourself for fun then scurrying to HR is kinda a slimy thing to do. As an admin you ha…

I think this is analogous to the philosophy behind "duty to report" type laws. If you discover -- even through a completely unrelated activity -- harm being done to someone, it is your ethical responsibility to report it to someone who can help. Obviously some amount of discretion is necessary, as some things are sensitive enough that reporting in the wrong way, or to the wrong person, could cause the situation to be worse, but as a general rule, if you see something bad going on, you should try to make the situation better if you're able.

I think OP acted entirely appropriately.

To address a couple specific points:

> As an admin you have an obligation to your users to not be nosy

In the free-wheeling academic sense where your users are more of a community, sure, I think that's the accepted social contract. In the workplace, not at all. While I'm not a fan of employers spying on what their employees do on the employer's network and hardware, I fully appreciate that it is their right to do so, and in some situations, for some purposes, I might even agree with its necessity.

> reading the plaintext yourself for fun then scurrying to HR is kinda a slimy thing to do

I don't think "fun" had anything to do with it, and reporting a likely case of sexual harassment, regardless of how the information was obtained, is never "slimy". Quite the opposite.

> Just because you have the ability to peek into the CFO's mailbox and see what everyone's salary is, doesn't mean you print out the spreadsheet and take it to your boss demanding a raise.

That is indeed slimy, unethical, and likely a violation of company policy, but that is not even remotely the same as what the OP did.

> if you got in trouble for playing Farmville or whatever while sitting on the toilet at work, which they found out about by installing cameras in the stalls

Also not even remotely the same. Any reasonable person would agree that cameras in bathroom stalls would be a gross violation of privacy (and probably illegal).

Re: Ken Thompson's Unix Password

#307

Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…

I'm conflicted about this. I know I'd be pretty upset if an employer starting talking to me about a plaintext password that's supposed to be hashed. The problem is that they brute forced it and then sent it directly off to HR? Yes, as a sysadmin it's perfectly acceptable to be searching for weak passwords, but reading the plaintext yourself for fun then scurrying to HR is kinda a slimy thing to do. As an admin you ha…

and to think of all the times i used passwords that were a some variation of “thisCompanySucks@$$!” or “B1llis@d!ck”...

Re: Ken Thompson's Unix Password

#308

Back when I worked in IT many years ago, one of the things I did each week was run JohnTheRipper on our password file. If it cracked your password, it sent you an email saying your password was weak and you had to change it. If you were in the next week's batch, it emailed you and told you "your password is foobar, which we discovered by cracking the password file, and it is weak. You must change it". Yes, I emailed…

What would be a weak creepy password? I feel those properties run opposite. Weak enough to be bruteforced and creepy enough to get fired. Good job on that fella’s part I would say!

Re: Ken Thompson's Unix Password

#309

Earlier quoted context omitted.

I'm conflicted about this. I know I'd be pretty upset if an employer starting talking to me about a plaintext password that's supposed to be hashed. The problem is that they brute forced it and then sent it directly off to HR? Yes, as a sysadmin it's perfectly acceptable to be searching for weak passwords, but reading the plaintext yourself for fun then scurrying to HR is kinda a slimy thing to do. As an admin you ha…

Yes, creepy sexists need our protection and it's exactly the same thing as playing farmville on the bathroom.

Please provide to me all of your personal details. Don't be alarmed. This is standard procedure. We just want to make sure you have the correct moral character to participate on this forum.

Browser and search history, email passwords, diaries, and a list of medical professionals that I can contact to vouch for your mental stability should suffice.

We will reach out in the next few days to conduct a character assessment review. Thank you for your cooperation!

If you have any questions, do not hesitate to fill out a form with the Health and Safety Commission offices. Our hours are 10 AM to 3 PM every other Tuesday of every other month.

Remember, your health and safety is important to us.

Re: Ken Thompson's Unix Password

#310
post #181
post #156

Earlier quoted context omitted.

I don't know what to think about this. A password is supposed to be secret so I don't know what a naughty phrase in secret is a violation of? It is not very different from writing something naughty in a private diary, or even thinking a naughty thing.

Not to mention "creepy" is a charge that is often impossible to defend yourself from. It's wholly dependent on the subjectivity of the accuser and their opinion of the accused. Walk over and say good morning every day to a coworker and she finds you attractive? Charming and sweet. Walk over and say good morning every day to a coworker and she finds you unattractive? Creepy.

No one cares about a purist stance on creepiness. Being creepy is enough to justify removal from any social or professional situation. If you lack the social skills to avoid being perceived as creepy, that's a you problem. It doesn't really matter what your rationalization is. People aren't going to want you around.
Post reply on HN