Earlier quoted context omitted.
You don't want to try 150 million Adobe logins on Disqus. You want to identify which ones to test first.
By linking your Disqus comments to your e-mail. For example your comments on sexual preference blogs, political blogs etc. Mapping your life, possibly opening up for blackmail.
Disqus cracked – Security flaw reveals users’ e-mail addresses
61–70 of 92 posts
Re: Disqus cracked – Security flaw reveals users’ e-mail addresses
#62Earlier quoted context omitted.
You don't want to try 150 million Adobe logins on Disqus. You want to identify which ones to test first.
Maybe I'm being dense this morning... if I were in the Adobe 150M, some criminals would already have my email address, right? How does getting Disqus's hash of it help them out?
Re: Disqus cracked – Security flaw reveals users’ e-mail addresses
#63Another reason to not use your real name or email address when commenting across the web.
Re: Disqus cracked – Security flaw reveals users’ e-mail addresses
#64Earlier quoted context omitted.
> I don't get it, if your email address is so private then why you share it with 3rd parties? How would you use it otherwise? My backyard is private, but I share it with a few 3rd parties. That doesn't mean i intent to share my backyard with the entire world. There is an element of trust with particular 3rd parties that is being violated. Why is that so hard to understand?
The address of your backyard is not private.
Re: Disqus cracked – Security flaw reveals users’ e-mail addresses
#65Re: Disqus cracked – Security flaw reveals users’ e-mail addresses
#66Re: Disqus cracked – Security flaw reveals users’ e-mail addresses
#67Re: Disqus cracked – Security flaw reveals users’ e-mail addresses
#68Earlier quoted context omitted.
Actually, yeah, it will be cracked, by someone . And E-Mail-addresses aren't passwords; trying a few hundred variations for each firstname for each lastname is perfectly feasible and should crack a nice percentage of these hashes.
My email is firstname@companyname.co.nz (I have a few of these at different companies). I'm fairly confident this isn't going to be cracked any time soon by random MD5 hashing. (of course, my real name can be extrapolated from my HN username)
Re: Disqus cracked – Security flaw reveals users’ e-mail addresses
#69Re: Disqus cracked – Security flaw reveals users’ e-mail addresses
#70Where does one get the dataset of email id's of Adobe users ?