Live data from Hacker News

Ken Thompson's Unix Password

leahneukirchen.org

521–530 of 665 posts

Re: Ken Thompson's Unix Password

#521

Earlier quoted context omitted.

I discovered that's the way my banking app actually worked until only a few updates ago. The password was originally limited to 8 characters (why this was the case for an online bank password is beyond me) but the app would allow you to enter more characters into the password input. It only accepted the first 8 characters though so anything you entered after those was ignored. I discoveres this when I mistyped my pas…

I’ve had the goddamn Citibank _require_ that I use a password 6 or 7 characters long on one of their systems. This year (2019).

Another bank I had around 3 years ago used only the 5 first characters, and these 5 first had to be numbers.

I guess anyone can just hack a password in like 1 second on a phone or something?

Re: Ken Thompson's Unix Password

#522
post #483

I remember cracking the password from a Windows system in high school. There was a centralized login mechanism using Novell but everything was cached locally. So you could boot a Linux CD and copy the password file to a memory stick, and crack at home. I think I used lophtcrack? The head admin account for the entire school district (basically root) had the password “north”. It took like a fraction of a second to crac…

Our high school network ran on Novell NetWare, but I wasn't anywhere near smart enough to crack anything so I just wrote a little program in QBASIC that looked like the NetWare login prompt which rejected all login attempts but dumped what was entered into a text file, and left it running on one of the PCs in the computer room. It wasn't even a compiled program, it was just running inside QBASIC's IDE. Yet it was run…

Hah, I and a friend did a very similar thing with our school's NetWare. We managed to get ours to silently log the user in after collecting the credentials so it was mostly invisible. We created it to get the password from a particular guy, but in true dragnet style we installed it on as many machines as we could.

I have no idea how network drives were managed with NetWare, but some students always managed to find world writable dirs (that shouldn't be). Then it was a matter of finding some obscure subdirectory, create a new one (typically containing alt+255 characters) and stick games there. Fun times.

We did get his password (and many others), but never actually did anything with it.

Re: Ken Thompson's Unix Password

#523
post #483

I remember cracking the password from a Windows system in high school. There was a centralized login mechanism using Novell but everything was cached locally. So you could boot a Linux CD and copy the password file to a memory stick, and crack at home. I think I used lophtcrack? The head admin account for the entire school district (basically root) had the password “north”. It took like a fraction of a second to crac…

Our high school network ran on Novell NetWare, but I wasn't anywhere near smart enough to crack anything so I just wrote a little program in QBASIC that looked like the NetWare login prompt which rejected all login attempts but dumped what was entered into a text file, and left it running on one of the PCs in the computer room. It wasn't even a compiled program, it was just running inside QBASIC's IDE. Yet it was run…

Reminded of my past experience and then remembered that already told that story:- https://news.ycombinator.com/item?id=17418559

Re: Ken Thompson's Unix Password

#524
post #23

I'm shocked at how well the old hashing stood up; sure, it's totally crackable today, but a well-picked password still took 4+ days to crack on modern hardware, which is remarkable. (Granted, it doesn't sound like they did anything fancy like throwing a hundred cloud instances at it or something; I'm not saying you should use DES today:) )

30 years ago I cracked everyone’s Unix password on an old Sun computer. It didn’t take long because everyone had a password that was in the dictionary. Needless to say, people were not happy with the messenger.

25 years ago I didn't need to crack anyone's unix passwords- they were all broadcasting them in cleartext every few minutes because they were using eudora or some other mail client, and I had converted an old sun workstation I found into a packet sniffer.

Re: Ken Thompson's Unix Password

#525

Earlier quoted context omitted.

I'm sorry that happened, that sounds like a terrible situation. Do you see how I took you at your word and extended sympathy, rather than questioning whether you're misrepresenting the situation? Is there something you know about the facts of jedberg's situation that lead you not to do the same?

He has not presented any facts that are under contention, only normative estimations that rely on facts that are deliberately unspecified. The politically and economically safe option in the workplace is always to discard people who fall under scrutiny that exposes an employer to liability. This raises the reasonable standard of complaint for these types of issues beyond "his password, which I cracked despite design…

[deleted]

Re: Ken Thompson's Unix Password

#526

Earlier quoted context omitted.

The guy wasn't fired for the password, he was fired for the sexual harassment of a coworker. And nothing you do on a work computer is secret from your employer. It's not a "private diary" if you're using your employer's hardware.

>he was fired for the sexual harassment of a coworker OP is vague on what this guy actually did. Note that they only went to the girl after cracking the password, and she said he was "creepy" towards her. "Creepy" in this context might just mean FWU (flirting while ugly).

[deleted]

Re: Ken Thompson's Unix Password

#527

Earlier quoted context omitted.

I'm sorry that happened, that sounds like a terrible situation. Do you see how I took you at your word and extended sympathy, rather than questioning whether you're misrepresenting the situation? Is there something you know about the facts of jedberg's situation that lead you not to do the same?

He has not presented any facts that are under contention, only normative estimations that rely on facts that are deliberately unspecified. The politically and economically safe option in the workplace is always to discard people who fall under scrutiny that exposes an employer to liability. This raises the reasonable standard of complaint for these types of issues beyond "his password, which I cracked despite design…

> The politically and economically safe option in the workplace is always to discard people who fall under scrutiny that exposes an employer to liability.

What leads you to believe this? You are aware, I assume, of the existence of "wrongful termination" lawsuits, many of which have cost companies millions of dollars?

> Can you think of a crackable-length passphrase that would make a normal, level-headed person suspicious

"rape Karen fun"

> fired in the worst way possible

What about this sounds to you like the worst way possible to get fired? Here are some ways to get fired that sound way worse to me:

"several frightening, anonymous calls that came into his work phone. One caller told him that [...] he wouldn’t live to see the weekend. Another said that the “fancy blue tie” he was wearing that day might wind up turning red. [...] an effort by the [company's] attorney to discredit him by falsely claiming he’d had a romantic relationship with [coworker he was standing up for]. Shortly afterward, [his employer] fired him."

"only two weeks after her hire, while she was in the passenger’s seat of [male employee]'s car returning from a business meeting, he exited the 101 freeway, stopped his car on a side street, and pulled his erect penis from his trousers. With the doors and windows locked from the driver’s side, he reached over “and pushed her head on his erect penis in an attempt to force her to orally copulate with him,” according to her complaint. He then ejaculated.

[her] horrifying depiction of sexual assault went on for pages. There was the ride back to the office after a client visit two days later, when [male employee] again tried to force her to touch his penis and “almost careened into a commercial eighteen-wheel vehicle.” Another time in the car, this time in standstill traffic, he took his erect penis out of his trousers and shoved her left hand back and forth on it, again ejaculating. In the complaint, she says she tried to free her hand but “was unable to overcome his strength.” In another incident, he called her into his office, locked the door behind her, and tried to force her to have sex. That time, the complaint says, she “managed to escape his grasp.”

A month after that frightening incident, [she] was fired by [him], purportedly for “an attitude problem, aversion to directions, resistance and resentfulness.” She told the office supervisor about [his] assaults and suggested that the “attitude problem” [he] had referred to was her resistance to his assaults. The supervisor told her that sort of workplace conduct was considered “normal”"

https://theintercept.com/2019/10/07/metoo-wall-street-sexual...

Re: Ken Thompson's Unix Password

#528

Earlier quoted context omitted.

What does the p/ part mean? My chess experiences is all after the popularity of descriptive notation...

p/q2-q4! p : pawn / : at q2 : queen's file, rank 2 - : moves to q4 : queen's file, rank 4 ! : good move!

Oh hmm, I didn't realize the notation was so unnecessarily verbose :) Of course it's a pawn moving from q2 to q2, that's the only thing there at the beginning of the game!

Re: Ken Thompson's Unix Password

#529
post #53
post #8

Earlier quoted context omitted.

The part before : is the hash, the part after is the cracked 8 character password.

Honestly, that confused me too. I really thought the whole password was that long.

Lol I‘m familiar with chess notation but was so confused by this that I was googling to see what chess move uses a “Z” :(

Re: Ken Thompson's Unix Password

#530
post #407

Earlier quoted context omitted.

I've never done anything malicious with the knowledge, but I've totally learned people's passwords just by watching their fingers type. I make an effort to have passwords that would be difficult for a human to nail down while watching them typed quickly in real time. The ubiquity of cameras has me reconsidering input and/or authentication mechanisms, though.

One good thing about using dvorak I guess

Especially with blank caps; securing keys through obscuring keys.
Post reply on HN