TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Millions of stolen Last.fm passwords have been decrypted. These are the top 50

26 点作者 brakmic超过 8 年前

5 条评论

tomp超过 8 年前
I wonder how much passwords like "lastfm", "music" and "abcdefg123" are an indication of people just being bad with security, as opposed to people just not giving a damn... Amid the overflow of trivial sites requiring more and more login details, is there really a value in having strong passwords? Personally, I mostly don't care; I have strong passwords for important sites (banks, online stores that have my credit card details), but for the rest of logins, I use pretty trivial passwords - if someone "steals" my account, I'll just create another one!
评论 #12416907 未加载
评论 #12416954 未加载
评论 #12416937 未加载
评论 #12416869 未加载
评论 #12417187 未加载
connoredel超过 8 年前
I feel like this is misleading without the % share of the total. These top 50 represent 2.7% of the total. OK, that sounds bad, but I&#x27;m not really sure how to interpret it.<p>Even if we get better at this, the top passwords will still be these, they&#x27;ll just be lower as a % of the total. So until we have 100% unique passwords, this story will always be there, which just seems lazy.
ancarda超过 8 年前
If you follow the link in the article to leakedsource.com, it says:<p><pre><code> Passwords were stored using unsalted MD5 hashing. </code></pre> It&#x27;s 2016... why is this still happening?
评论 #12416944 未加载
onethumb超过 8 年前
This has been my go-to for passwords for awhile. Top 100, 500, 1000, etc all the way to millions. <a href="https:&#x2F;&#x2F;github.com&#x2F;danielmiessler&#x2F;SecLists&#x2F;tree&#x2F;master&#x2F;Passwords" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;danielmiessler&#x2F;SecLists&#x2F;tree&#x2F;master&#x2F;Passw...</a>
thenewwazoo超过 8 年前
I do hobby research into password guessing entropy and I&#x27;d love to get ahold of these lists of in-the-wild passwords. Is there any good source for such things? I don&#x27;t need usernames, just &quot;real&quot; passwords (with frequency data if I can get it).
评论 #12416931 未加载