TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

YouPorn passwords available for download, thousands of users exposed

52 点作者 bleakgadfly大约 13 年前

18 条评论

pstatho大约 13 年前
I'm CTO for Manwin Canada and ultimately responsible for YouPorn.<p>It's unfortunate that people are associating chat.youporn.com to the actual YouPorn.com site, but they are not affiliated at all. It was operated by a completely separate entity, which we've obviously closed as soon as we discovered it. The accounts on chat.youporn.com are different than the accounts on YouPorn. Though as was mentioned, it is probably that some have re-used the same username password combination that is highly unrecommended for all you folks out there (if you read Hacker News, you already know that).<p>As for password policies, I've been enforcing hashing of passwords ever since joining, though as we inherit a lot of old code and sites we correct issues such as that as we come across them.<p>I'll be around for a while, if anyone wants to ask questions.
评论 #3623144 未加载
评论 #3623375 未加载
评论 #3623110 未加载
评论 #3623181 未加载
评论 #3623131 未加载
评论 #3625402 未加载
评论 #3623347 未加载
rdl大约 13 年前
<a href="http://blog.youporn.com/youporn-data-not-exposed/" rel="nofollow">http://blog.youporn.com/youporn-data-not-exposed/</a><p>It was actually the passwords to YP Chat, not Youporn itself. The Yourporn guys are pretty reasonable engineers and sysadmins, from what I've seen, and manage user passwords correctly.<p>Personally, I think in 2012, if you're not using a password manager to generate and manage unique, strong passwords per site, especially for "sketchy" stuff like porn sites, you're already doomed.<p>Also, Presidents Day and other minor useless holidays are great times for annual rituals like tracking down and changing any legacy shared passwords you may have. Don't wait for a breach!
评论 #3623098 未加载
评论 #3623074 未加载
pjscott大约 13 年前
How many sites need to be humiliated like this before people learn to hash passwords with something like bcrypt? It's like two damn functions. You just call them! It's so easy that even a baby squirrel could do it! There is no excuse.<p>Until then, I hope everyone is using a throwaway password for accounts that can be non-disastrously stolen, and using strong unique passwords for the important ones.
评论 #3622968 未加载
评论 #3622834 未加载
评论 #3622999 未加载
评论 #3623211 未加载
评论 #3623140 未加载
评论 #3623075 未加载
laconian大约 13 年前
Kudos on the double entendre in the title, intentional or not.
评论 #3622991 未加载
NelsonMinar大约 13 年前
Top 10 domains: 1469 yahoo.com / 1071 hotmail.com / 882 gmail.com / 205 hotmail.co.uk / 178 web.de / 136 gmx.de / 127 aol.com / 116 hotmail.de / 115 live.com / 104 hotmail.fr<p>Top 10 passwords: 110 123456 / 75 123456789 / 30 12345 / 23 melinda / 19 fuck / 18 1234567890 / 17 Nightmare / 16 allzen / 15 password / 15 anal<p>That's of about 6400 records.
评论 #3623405 未加载
ahel大约 13 年前
<a href="http://pastebin.com/yJ8JU45W" rel="nofollow">http://pastebin.com/yJ8JU45W</a>
Kiro大约 13 年前
Everything was on <a href="http://chat.youporn.com/tmp/" rel="nofollow">http://chat.youporn.com/tmp/</a> completely open to the public so this is an even bigger screw-up than the fact that they didn't hash their passwords.
joejohnson大约 13 年前
Link to the password dump: <a href="http://pastebin.com/ieC6eTB7" rel="nofollow">http://pastebin.com/ieC6eTB7</a>
评论 #3623036 未加载
rokhayakebe大约 13 年前
Why would anyone sign up for a porn site with their main email address? What baffles me even more is how some people actually whip out their credit card and give the digits to a porn site.
评论 #3623092 未加载
aaronpk大约 13 年前
Someone should make a site where you sign in with your Gmail account and find out how many of your contacts have youporn accounts.
评论 #3623107 未加载
te_chris大约 13 年前
And all this after all the press about them moving their entire stack to Redis etc etc. How can a company achieve such an epic technical feat and have shitty password hashing?
评论 #3623020 未加载
___Calv_Dee___大约 13 年前
I don't understand how this makes it to Top News. I think at this point we are all well aware that no user-password store is impenetrable or invulnerable and porn websites would hardly be an exception. If you do not know by now that you should not be using the same password across multiple accounts, it seems like there is little hope. There is no lesson to be learned here. Is it not an implicit assumption that if you subscribe to a porn website someone is mostly likely going to find out one way or another?<p>1. Don't reuse passwords. 2. Don't subscribe to porn sites if you have something to lose from someone finding out.
评论 #3623120 未加载
jamesu大约 13 年前
This has been passed around a certain anonymous messageboard for the better part of a week now, i'm surprised sophos has taken this long to write anything about it!
shadowed大约 13 年前
Bonus: it appears YouPorn has no way to change your password, nor any way to change (or even see) the email address that is associated with your account.
paul9290大约 13 年前
Always good to have a throwaway email, username and password for sites like this and others you care little about.
评论 #3623089 未加载
mycodebreaks大约 13 年前
How do passwords get leaked? Does it mean they were stored in plain text?
verelo大约 13 年前
so who is going to be the first person to parse this out and determine what the most commonly used password is?<p>Any bets on asdfghjkl;' ??<p><i>i think i'll do this tonight</i>
评论 #3624609 未加载
评论 #3623732 未加载
uvTwitch大约 13 年前
YouPorn: where everything is exposed.