Live data from Hacker News

Ken Thompson's Unix Password

leahneukirchen.org

641–650 of 665 posts

Re: Ken Thompson's Unix Password

#641
post #512

Earlier quoted context omitted.

That is an understatement. I wonder what kind of backstabber he grew up to be :/

The concerned kind. Refusing to keep their mouth shut when others exploit the system. This is a problem, here GP is a hero, a hacker, a free spirit. But there is no point in romanticizing such behavior. If you find a vulnerability in a system, you disclose it to the people that should know about it. You can do that anonymously, or you can alert people in a subtle way. What you don't do is sit on it and brag to people…

What the OP did is (in this case) irrelevant to what the asshole did. There were multiple ways he could have gone about dealing with the situation that did not involve fucking someone over, but he chose to do that instead.

I just cannot attribute something like that to altruism.

Re: Ken Thompson's Unix Password

#642

Earlier quoted context omitted.

Would this suggest that 3DES with a sufficiently long password is still safe for now?

This suggests you don't understand how DES-based crypt() worked, so let's take both angles here: 1. Would it be safe to build a password hash like crypt() based on 3DES today? Maybe, kind of, it depends, don't do this. "Based on" is key here. You'd have to come up with some way to try to use 3DES in this fashion, just as the developers of Unix crypt() used DES. Basically you're trying to build a cryptographic hash ou…

Thanks for the great answer. I am not familiar with DES but the reason I wondered about this is because I saw that some VPN hardware devices still has 3DES as an option and even as the default encryption algorithm. I was really baffled by this because I had assumed that 3DES has completely fallen out of favor. So I guess the company isn't choosing sensible defaults. But at the time, I thought maybe they knew something I didn't (although I still switched the algorithm to AES since there's no reason not to).

Re: Ken Thompson's Unix Password

#643

Earlier quoted context omitted.

A lot of them will use an algorithm similar to this one https://www.jwz.org/doc/threading.html

Great read! Just noting that the website redirects you to an obscene (but funny) image if this site is the Referer. Disable Referer before clicking or copy the link into the toolbar manually.

Incidentally, forgetting I had inverted colors for nighttime reading, to me the image looked like a fuzzy peach colored microphone or something similar. Took me a while to figure out how it was obscene! :)

Re: Ken Thompson's Unix Password

#644
post #641

Earlier quoted context omitted.

The concerned kind. Refusing to keep their mouth shut when others exploit the system. This is a problem, here GP is a hero, a hacker, a free spirit. But there is no point in romanticizing such behavior. If you find a vulnerability in a system, you disclose it to the people that should know about it. You can do that anonymously, or you can alert people in a subtle way. What you don't do is sit on it and brag to people…

What the OP did is (in this case) irrelevant to what the asshole did. There were multiple ways he could have gone about dealing with the situation that did not involve fucking someone over, but he chose to do that instead. I just cannot attribute something like that to altruism.

Listen, knowing only OP's side of the story it's easy to sympathize. Especially if he's a part of our inngroup of technical people.

Dismissing the whistle-blower as a "kid, that wanted to just fuck someone over" is hardly fair.

Re: Ken Thompson's Unix Password

#645
post #253

Earlier quoted context omitted.

I agree, - but morality is sticky and complex. It was obviously wrong to be the creepy sexist. In the abstract sense, it is wrong to invade privacy. But then, if in your invasion of privacy you uncover a wrongdoing, the right thing to do is report it. It would be wrong to read the CFO's email inbox, and probably illegal. But then if you uncover they are committing fraud, you need to report it to police, as well as co…

You said "... but morality is ..." and just agreed with me, I think? Ultimately, I think it's a case-by-case on this type of thing. Btw, I find it very interesting that e.g. most EU courts will consider "tampered-with" evidence, but obviously take into account that it may have been tampered with and so accord it much less weight than "pristine" evidence. Whereas US courts will[0] absolutely throw out anything that's…

I agreed. I just wanted to take it a stage further and emphasise the definition of 'wrong' is always complex in moral discussions.

Re: Ken Thompson's Unix Password

#646
post #359

Earlier quoted context omitted.

I get what you're saying here but: >In the abstract sense, it is wrong to invade privacy. You have no real expectation of privacy when using company owned equipment. This was almost certainly spelled out to the employee in question in the acceptable use policy he agreed to upon being hired. Companies have to operate this way so they can investigate computers if compelled to by court or law, and so they can recover im…

The definition of acceptable use (and expectations of privacy) differs a lot between different countries. For example, in the EU, I believe that any personal email received on a work account is actually considered "beyond reach" of your employer. I don't know , but I imagine that such considerations could easily extend to your password. Btw, how did the sysop know that what he recovered was the actual password? I mea…

That is true, there are stronger privacy protections in the EU in general. I don't consider the actions here morally justifiable, just legally.

As far as it being the actual password, a false positive AND the fact he had been creeping on a coworker at the same time seems extraordinarily unlikely to me.

Re: Ken Thompson's Unix Password

#647
post #641

Earlier quoted context omitted.

What the OP did is (in this case) irrelevant to what the asshole did. There were multiple ways he could have gone about dealing with the situation that did not involve fucking someone over, but he chose to do that instead. I just cannot attribute something like that to altruism.

Listen, knowing only OP's side of the story it's easy to sympathize. Especially if he's a part of our inngroup of technical people. Dismissing the whistle-blower as a "kid, that wanted to just fuck someone over" is hardly fair.

snitch

Re: Ken Thompson's Unix Password

#648
post #281

Earlier quoted context omitted.

I'm not sure how easy that is to remember... Was it 'really love but wish' or 'love but really wish'? etc.

I suspect you would word your password in a way that is most familiar for you. The idea is to achieve both cognitive comfort while destroying brute force efforts. A better example: Antidisestablishmentarianism is the longest English word I can think of## 73 characters.

I think you'd have more fun trying to imagine phrases no one would ever say.

"But thankfully I took Kim Kardashian's advice, and everything worked out for the best."

Re: Ken Thompson's Unix Password

#649
post #348
post #179

Earlier quoted context omitted.

Actually, it's a rather perfect analogy. People have some expectations of privacy and it's not normally considered acceptable to violate this. Sometimes this stuff is untried in court or falls into a definite legal grey area and usually the policy is to err on the side of caution and simply assume that if something is commonly expected to be private, then it's private and should be kept so. If we were investigating a…

It's an absolutely terrible analogy. First off, putting cameras in restrooms is illegal in most places. Regardless of that, it boils down to a legitimate company need. Ensuring that users aren't using passwords definitely passes that test. Ensuring that employees aren't sexually harassing other employees also definitely passes that test. Yes, it's unusual that a password tipped people off to bad behavior, but if you…

To expand on the company need angle, logging in to your work account on your work computer hardware is absolutely a part of your job. Work has a vested interest in securing their computer systems while allowing authorized employees only to use them to conduct their work.

On the other hand, going to the bathroom is completely ancillary to your job. It's not a work-related duty; it's just something that humans have to do because we're made out of meat.

Re: Ken Thompson's Unix Password

#650
post #155

I still have 0 idea what's interesting about this. How is this a chess move?

the password is the last part: p/q2-q4! it's a notational way in the chess program (written by Ken Thompson) to describe a chess move, "pawn from Queen's 2 to Queen's 4." A very common opening move that "puts a pawn in the center, controlling the important e5-square, and opens the line for the Bc1."[1] The notation is old. Modern notation would just write it as "d4" because there's only one piece (a pawn) who can mov…

> the chess program (written by Ken Thompson)

AHHHH thank you this makes much more sense now

Post reply on HN