Live data from Hacker News

I Am Releasing Ten Million Passwords

xato.net

71–80 of 229 posts

Re: I Am Releasing Ten Million Passwords

#71
post #64
post #36

Earlier quoted context omitted.

And then history -c

... which will clear your entire history, which you probably don't want. I don't know a shorter way, but to delete one line from history, do 'history', which shows the line numbers, then 'history -d LINE_NUM'. Or, in bash, prepend the command with a space and it won't go into history.

Open new terminal -> unset HISTFILE -> do your greping -> close terminal

Re: I Am Releasing Ten Million Passwords

#72
post #50

Earlier quoted context omitted.

What about research to determine to what extent usernames with words in a certain language will tend to use passwords with words for the same language? (More generally, is there any connection between the bi- or trigram distribution on usernames and the one on passwords? In fact, do they just look the same, or could you tell given a string whether it's more likely a username or a password?) Do usernames of people wit…

I feel like most of those research questions could be answered if it was a "username -> password strength" mapping, in addition to a hash to study duplicate trends, rather than just "username -> password". Obviously there is no objective ranking of "password strength", but a decent approximation could be provided. There are serious risks to having your username and password in a public list. Yes, all of these usernam…

As I explained in the article I seriously doubt that any more than a tiny number of these passwords are still valid. And there is no reason for them to be, having already been widely available, indexed (and cached) by every search engine, archived at archive.org, and downloaded by thousands or tens of thousands of people. Anyone who would use this data maliciously probably already has it.

Much of this data is the same data monitored by sites like haveibeenpwned.com and a dozen others. Facebook scrapes these. Lastpass will send you alerts. The risk here is minimal; the research value is much more than you realize.

Re: I Am Releasing Ten Million Passwords

#73

It seems very useful for research and also practical uses, like how about a REST API with this dump? get will not only return true if it exists but how common and how weak it is, or will return a false for unique. Is there such a service out there?

This seems a bit like testing if your parachute was packed properly by deploying it. Once I've sent my password at a 3rd party API, it doesn't much matter what the API says: my password is no longer secure.

Re: I Am Releasing Ten Million Passwords

#74

Fun! $ export LC_ALL='C' $ awk '{ print $2 }' 10-million-combos.txt | tr 'A-Z' 'a-z' | sort | uniq -c | sort -nr | head -n 20 55893 123456 20785 password 13582 12345678 13230 qwerty 11696 123456789 10938 12345 6432 1234 5682 111111 4796 1234567 4191 dragon 3845 123123 3734 baseball 3664 abc123 3655 football 3330 monkey 3206 letmein 3136 shadow 3126 master 3050 696969 3002 michael Edit: I used Wordle[1] to make a word…

I'm surprised (disappointed?) only 1 person used "correcthorsebatterystaple".

Re: I Am Releasing Ten Million Passwords

#75

This is great, but if you use a password manager, it's very difficult to determine which, if any, of your accounts would be compromised. For myself, this would just be doing a dump and looping a few greps. But for family and friends, does anyone have any ideas for a less technical audience?

1password has a limited ability to warn you of compromised passwords. they maintain a database of breaches that they warn you about in their client. the warning, however, is much less prominent than it probably should be

Re: I Am Releasing Ten Million Passwords

#76
post #72

Earlier quoted context omitted.

I feel like most of those research questions could be answered if it was a "username -> password strength" mapping, in addition to a hash to study duplicate trends, rather than just "username -> password". Obviously there is no objective ranking of "password strength", but a decent approximation could be provided. There are serious risks to having your username and password in a public list. Yes, all of these usernam…

As I explained in the article I seriously doubt that any more than a tiny number of these passwords are still valid. And there is no reason for them to be, having already been widely available, indexed (and cached) by every search engine, archived at archive.org, and downloaded by thousands or tens of thousands of people. Anyone who would use this data maliciously probably already has it. Much of this data is the sam…

>Anyone who would use this data maliciously probably already has it.

You might be surprised. The fact that these dumps are supposedly quite old certainly mitigates the risk, but I've seen cases of primary email accounts being taken over from a plaintext password in a dump 5+ years old. No one ever tried it on the email because it wasn't in the dump and wasn't identical to the username, though it was very close.

Aggregators like haveibeenpwned.com and Lastpass responsibly use the passwords they scrape, they don't release them all in a big batch like this. Many cybercriminals do the same kind of scraping and share these aggregated lists privately, but they're always going to be missing things, so there's no question they're all going to be pulling in your list, too. And odds are there's going to be at least one dump that a lot of them missed which yours has.

I do understand there is some research benefit here, but even in the best possible scenario I don't think the value from the research outweighs the costs.

Re: I Am Releasing Ten Million Passwords

#77
post #22
post #17

Earlier quoted context omitted.

The trafficking charges were dropped but he still was charged as an accessory after the fact. http://cryptome.org/2015/01/brown-105.pdf

Yes; that's #1 in my list. Thanks for the link to the sentencing memo!

I never followed the case, could someone clarify how he was an accessory after the fact?

Did they explain how he misled Stratfor? Were they investigating their own breach and contacted him somehow? Or did he hide evidence?

It'd be great to have clarity on his wrongdoing related to the hacking. The parts about threats and hiding evidence seem tertiary to peoples defense of him. Since the major crime that he became famous for was the hacking by anonymous.

Re: I Am Releasing Ten Million Passwords

#78
post #3

Barrett Brown was not convicted merely for linking to data on the web. He was convicted for three separate offenses: 1. Acting as a go-between for (presumably Jeremy Hammond) the Stratfor hacker and Stratfor itself, Brown misled Stratfor in order to throw the scent off Hammond. Having intimate knowledge of a crime doesn't make one automatically liable for that crime, but does put them in a precarious legal position i…

I don't know, sounds like he got off pretty lightly considering he threatened an FBI agent's children. I would expect the jail time would be a lot higher, but I guess I don't know what guides the court's decisions in these kinds of cases. I suppose five is enough time for him to figure out the error of his ways.

His sentence was dominated by the accessory charge, and the threats don't seem to have been a factor at all.

Re: I Am Releasing Ten Million Passwords

#79
post #77
post #22

Earlier quoted context omitted.

Yes; that's #1 in my list. Thanks for the link to the sentencing memo!

I never followed the case, could someone clarify how he was an accessory after the fact? Did they explain how he misled Stratfor? Were they investigating their own breach and contacted him somehow? Or did he hide evidence? It'd be great to have clarity on his wrongdoing related to the hacking. The parts about threats and hiding evidence seem tertiary to peoples defense of him. Since the major crime that he became fam…

According to Kim Zetter:

The first charge is a new one and relates to assistance Brown allegedly gave the person who hacked Stratfor “in order to hinder and prevent [his] apprehension, trial and punishment.”

According to the government Brown worked to create confusion about the hacker’s identity “in a manner that diverted attention away from the hacker,” which included communicating with Stratfor after the hack in a way that authorities say drew attention away from the hacker. The hacker is not named, and it’s not clear if it’s convicted Stratfor intruder Jeremy Hammond, or an earlier hacker who’s known to have penetrated the company first.

Re: I Am Releasing Ten Million Passwords

#80
post #79
post #77

Earlier quoted context omitted.

I never followed the case, could someone clarify how he was an accessory after the fact? Did they explain how he misled Stratfor? Were they investigating their own breach and contacted him somehow? Or did he hide evidence? It'd be great to have clarity on his wrongdoing related to the hacking. The parts about threats and hiding evidence seem tertiary to peoples defense of him. Since the major crime that he became fam…

According to Kim Zetter: The first charge is a new one and relates to assistance Brown allegedly gave the person who hacked Stratfor “in order to hinder and prevent [his] apprehension, trial and punishment.” According to the government Brown worked to create confusion about the hacker’s identity “in a manner that diverted attention away from the hacker,” which included communicating with Stratfor after the hack in a…

Thanks. Seems like during sentencing this was the key point related to accessory:

> Loss amount of more then $400,000 but less than $1M

This was worth +14 points which was higher than any other single guideline - including threatening an FBI agent.

I guess the lesson here is that if the crime at hand involved any significant amount of money then even if your role was minor (and after the fact) you can still get serious punishment.

Post reply on HN