Stop giving your users passwords to Troy Hunt! Eg. hash and salt them! But use a really slow hash . Lets say the hashing speed is one hash per second, then it would take trillion years to brute force the password "hello".
I don't think you understand how he gets ahold of these passwords. They're from dumps of leaked databases.
86% of CrashCrate subscribers used passwords already leaked in other breaches
61–70 of 145 posts
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#62At bare minimum websites should use 2FA - a simple TOTP on any smartphone will do wonders. But, the issue is that 86% of all websites offer so little value that 86% of people would just not bother using the site if they had to do the 2FA dance each time. That is the fundamental problem here - not people reusing passwords, or password policies that break when encountering my password manager. It's not surprising peopl…
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#63When I feel like a security goon's arbitrary and capricious password policy is irrational and counterproductive, I make my passwords worse in the hopes that I have to someday read it to someone, or perhaps it gets spilt outin the open, and then everyone will see how forcing me to pick a password that adheres to certain characteristics solved nothing. Just wait. Someday you will see dumps of pwnt password that look li…
G0Fuc4Y@urse!f
To me this is a sure way that people are gonna pick horrible and stupid passwords.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#64Earlier quoted context omitted.
1. With a password manager, you don't have to think anymore if a site is high-consequence or low-consequence. 2. What kinds of websites that require a sign-in are actually low-consequence? I can't think of any from the top of my head, but that's probably because I'm pretty reluctant to sign up to new sites.
To be honest, the first one that comes to mind is HN. There is zero consequence if someone was to get a hold of my credentials here — I don't care about the score and I can still recover the bookmarks.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#6586% of my passwords are for low consequence sites. How much should I care if someone hacks my handle and posts ads on a chat site? Or reads registration-required articles under my registration? Or etc etc.
If you ever reuse that password anywhere else, then you should care A LOT. If you go "i only reuse passwords on low-consequence sites", then I have to ask you 1) why reuse at all? and 2) are you sure? I bet that that's not true, I bet you think that's true but it turns out that your Uber password is the same as your RandomSite password. Just use a password manager. It's easier and it's safer, and you never have to th…
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#66Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#67Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#68If IT people can't get this right, it's impossible for the average person to EVER get this right. We need a better solution.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#69Earlier quoted context omitted.
If you ever reuse that password anywhere else, then you should care A LOT. If you go "i only reuse passwords on low-consequence sites", then I have to ask you 1) why reuse at all? and 2) are you sure? I bet that that's not true, I bet you think that's true but it turns out that your Uber password is the same as your RandomSite password. Just use a password manager. It's easier and it's safer, and you never have to th…
Unfortunately, OSs don't make it easy to use password managers, especially in mobile. A lot of my banking sites also defeat my password manager with bizarre UX like user name masking and multi step login screens.
Re: 86% of CrashCrate subscribers used passwords already leaked in other breaches
#70Earlier quoted context omitted.
To be honest, the first one that comes to mind is HN. There is zero consequence if someone was to get a hold of my credentials here — I don't care about the score and I can still recover the bookmarks.
What if the person that takes over the account posts messages that arouse the interest of authorities? Your IP addresses and other info are associated with the account.