TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Password leaks bigger than first thought

33 pointsby bondalmost 13 years ago

8 comments

MehdiEGalmost 13 years ago
"And one amusing detail – although eHarmony implores its users to use strong passwords including both upper and lower case letters, it saves the passwords in all upper case"<p>This is truly beautiful - made my day :)
评论 #4092193 未加载
waffle_ssalmost 13 years ago
Unsurprising that &#62;95% of the password hashes have been broken. I remember being annoyed when I signed up for LinkedIn (just checked my tweet history - it was 2010/06/10) because they were only allowing 16 characters in the password field.<p>EDIT: Whoops, guess I should have done some napkin math before claiming that there are rainbow tables that cover that area. /me slaps wrist
评论 #4089536 未加载
评论 #4089625 未加载
评论 #4089525 未加载
评论 #4089540 未加载
ams6110almost 13 years ago
<i>Last month Last.fm admitted to having received several reports of spamming involving user data.</i><p>Over the last 6--9 months I have definitely noticed an uptick in the random "connection" requests I get on LinkedIn. I don't know if this is because their userbase has grown and more people are just shotgunning connection requests, or if these represent first steps at an attempted social engineering attack via hacked accounts on which I appear in the "people you might know."<p>So far none of these have been from people I actually know even remotely, so I'm guessing it's just simple spam (and I report it as such).
lomegoralmost 13 years ago
I find it really incredible that this companies were so careless. Really. I know that security practices are rare to come by, but come on! LinkedIn, eHarmony and last.fm! These are some of the biggest websites.
评论 #4089344 未加载
评论 #4089324 未加载
Havocalmost 13 years ago
Unsalted hashes. Wow. What a bunch of amateurs.<p>Also, 10 internet points says at least one other major website will fall too within 2 weeks. Someone has found a new exploit &#38; is trying various sites &#38; collecting hashes.
评论 #4089777 未加载
chrischenalmost 13 years ago
"The API was developed 9 years ago, and appears not to have been updated since."<p>Last.fm could have updated this, except it would have meant making all their users do something.
评论 #4089770 未加载
zizeealmost 13 years ago
What do people think about outsourcing your authentication to someone else?<p>Full Disclosure: I'm currently working on a brandable authentication host (<a href="http://www.authic.com" rel="nofollow">http://www.authic.com</a>) that will outsource the pain of storing your password hashes securly and provide your web app with slick a user account UX.
评论 #4090369 未加载
评论 #4089543 未加载
评论 #4089736 未加载
TrevorJalmost 13 years ago
Does the number of passwords in the hashed list matter in terms of how easy or hard they will be to crack? Does this have implications for a rainbow table-type attack?
评论 #4089568 未加载
评论 #4089307 未加载