Live data from Hacker News

Disqus cracked – Security flaw reveals users’ e-mail addresses

cornucopia-en.cornubot.se

91–92 of 92 posts

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#91
post #14

Earlier quoted context omitted.

Actually, yeah, it will be cracked, by someone . And E-Mail-addresses aren't passwords; trying a few hundred variations for each firstname for each lastname is perfectly feasible and should crack a nice percentage of these hashes.

My email is firstname@companyname.co.nz (I have a few of these at different companies). I'm fairly confident this isn't going to be cracked any time soon by random MD5 hashing. (of course, my real name can be extrapolated from my HN username)

$500 graphics cards can run a dictionary against a md5 hash at the rate of 700,000,000 per second. That is 0.7 billion per second.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#92

Earlier quoted context omitted.

The news is that Disqus is relying on that.

So does Automattic with gravatars (on nearly 20% of the internet, no less), and pray tell how many other companies that use md5(email) as a unique ID for a reason or another. Duh! What were they thinking!

I don't know what they were thinking. It's wrong, they shouldn't violate their users privacy like that.
Post reply on HN