Live data from Hacker News

Disqus cracked – Security flaw reveals users’ e-mail addresses

cornucopia-en.cornubot.se

61–70 of 92 posts

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#61

Earlier quoted context omitted.

You don't want to try 150 million Adobe logins on Disqus. You want to identify which ones to test first.

By linking your Disqus comments to your e-mail. For example your comments on sexual preference blogs, political blogs etc. Mapping your life, possibly opening up for blackmail.

Well I guess risk profiles vary. I'm certainly more worried about criminals having the access they need to reset my creds with various services, than about them knowing my oddball political opinions. I still don't see how this Disqus issue makes Adobe worse, although admittedly any big list of email addresses (like Adobe) makes this worse.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#62

Earlier quoted context omitted.

You don't want to try 150 million Adobe logins on Disqus. You want to identify which ones to test first.

Maybe I'm being dense this morning... if I were in the Adobe 150M, some criminals would already have my email address, right? How does getting Disqus's hash of it help them out?

Not being dense at all, it's a valid point, but crossing both leaks helps them find out quickly which logins and password combos to try at disqus, and which accounts will be compromised.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#64

Earlier quoted context omitted.

> I don't get it, if your email address is so private then why you share it with 3rd parties? How would you use it otherwise? My backyard is private, but I share it with a few 3rd parties. That doesn't mean i intent to share my backyard with the entire world. There is an element of trust with particular 3rd parties that is being violated. Why is that so hard to understand?

The address of your backyard is not private.

Analogies are terrible. "Imagine X is like Y. Ok, but what about aspect Z of Y? Oh, that doesn't apply to X."

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#66
post #63
post #43

Another reason to not use your real name or email address when commenting across the web.

Or you know just be a decent person and not post things you wouldn't say in person yourself.

Yeah - people have never been persecuted for who they are in person.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#68
post #14

Earlier quoted context omitted.

Actually, yeah, it will be cracked, by someone . And E-Mail-addresses aren't passwords; trying a few hundred variations for each firstname for each lastname is perfectly feasible and should crack a nice percentage of these hashes.

My email is firstname@companyname.co.nz (I have a few of these at different companies). I'm fairly confident this isn't going to be cracked any time soon by random MD5 hashing. (of course, my real name can be extrapolated from my HN username)

They are after a specific list of politicians which the email addresses are probably known already. So there is no security. Hashing and hashing with salt only protects population, not individual with knowledge.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#69
post #63
post #43

Another reason to not use your real name or email address when commenting across the web.

Or you know just be a decent person and not post things you wouldn't say in person yourself.

Common Sense, The Federalist Papers, Candide ...
Post reply on HN