[url=http://meincmagazine.com/civis/viewtopic.php?p=28156961#p28156961:ibp87v0u said:epixoip[/url]":ibp87v0u]But in no way should anyone draw the conclusion that PHPass is a poor password hashing algorithm, especially if your basis for that decision is "because MD5."
Bieber, being a regular person, has a Gmail account, which has a 8 character minimum.[url=http://meincmagazine.com/civis/viewtopic.php?p=28157651#p28157651:2slaf9ol said:mehaase[/url]":2slaf9ol][url=http://meincmagazine.com/civis/viewtopic.php?p=28156961#p28156961:2slaf9ol said:epixoip[/url]":2slaf9ol]But in no way should anyone draw the conclusion that PHPass is a poor password hashing algorithm, especially if your basis for that decision is "because MD5."
I'm learning a lot and this has been a fascinating conversation for me, but I don't know where you or your friend got the idea that my whole argument was "because MD5". Let me try grounding this in a practical attack:
1. The attacker has e-mails and hashes.
2. This is where you say, "who cares? the attacker can't brute force _all_ of the passwords because PHPass."
3. The attacker finds a high-value target e-mail. Umm, let's say Justin Bieber is a huge fan of Ars Technica.
4. Justin happens to have a 6 char password because he's an ordinary person, not a security freak like us.
5. Attacker brute forces Justin's password in 14 days or less. (Not 7 days or less as I originally guessed — my bad!)
6. This is where the "who cares? it's just a forum!" crowd chimes in.
7. Attacker tries same password on Justin's email account, which works because Justin is an ordinary person, not a security freak like us. (And the email provider also has a mystifying 6 character minimum, just like Ars.)
8. Profit.
I'm not "hung up" on any particular algorithm. Let's just say that there are several simple ways that Ars could have turned 14 days into 14 years (or more). If this was any other site, I'd shrug and say, "oh well." But Ars covers password cracking! I can't believe that you and your buddy fail to see the irony here.
Anyway, who cares... This breach doesn't affect me personally, and if other people can't be bothered to pick good passwords then they deserve what's coming. Right?
I'll stop arguing.
[url=http://meincmagazine.com/civis/viewtopic.php?p=28157651#p28157651:336b4htu said:mehaase[/url]":336b4htu]
3. The attacker finds a high-value target e-mail. Umm, let's say Justin Bieber is a huge fan of Ars Technica.
Any high-value target that reads Ars will be somebody like Bruce Schneier or somebody else that knows better than to use an easily crackable 6 character password. I mean, even an actor like Wil Weaton knows better than that. (Though maybe not an actor like Kirk Cameron...)[url=http://meincmagazine.com/civis/viewtopic.php?p=28157651#p28157651:2t8qp7zd said:mehaase[/url]":2t8qp7zd]3. The attacker finds a high-value target e-mail. Umm, let's say Justin Bieber is a huge fan of Ars Technica.
4. Justin happens to have a 6 char password because he's an ordinary person, not a security freak like us.
I'm also stunned that both of you think of Justin Beiber as an "ordinary person"[url=http://meincmagazine.com/civis/viewtopic.php?p=28157889#p28157889:2t8qp7zd said:somini[/url]":2t8qp7zd]Bieber, being a regular person, has a Gmail account, which has a 8 character minimum.
[url=http://meincmagazine.com/civis/viewtopic.php?p=28157961#p28157961:3pc7d5u4 said:Dark Steve[/url]":3pc7d5u4]Any high-value target that reads Ars will be somebody like Bruce Schneier or somebody else that knows better than to use an easily crackable 6 character password. I mean, even an actor like Wil Weaton knows better than that. (Though maybe not an actor like Kirk Cameron...)[url=http://meincmagazine.com/civis/viewtopic.php?p=28157651#p28157651:3pc7d5u4 said:mehaase[/url]":3pc7d5u4]3. The attacker finds a high-value target e-mail. Umm, let's say Justin Bieber is a huge fan of Ars Technica.
4. Justin happens to have a 6 char password because he's an ordinary person, not a security freak like us.
I'm also stunned that both of you think of Justin Beiber as an "ordinary person"[url=http://meincmagazine.com/civis/viewtopic.php?p=28157889#p28157889:3pc7d5u4 said:somini[/url]":3pc7d5u4]Bieber, being a regular person, has a Gmail account, which has a 8 character minimum.![]()
[url=http://meincmagazine.com/civis/viewtopic.php?p=28157651#p28157651:1ox8homz said:mehaase[/url]":1ox8homz]I'm not "hung up" on any particular algorithm. Let's just say that there are several simple ways that Ars could have turned 14 days into 14 years (or more). If this was any other site, I'd shrug and say, "oh well." But Ars covers password cracking! I can't believe that you and your buddy fail to see the irony here.
[url=http://meincmagazine.com/civis/viewtopic.php?p=28158021#p28158021:28t2v07n said:TheMerricat[/url]":28t2v07n]
Seriously, if JB is hacked - it'll be highly unlikely that Ars will have proven to be the weakest link in the chain here.
When I try, I get "A technical issue has occurred on web08."[url=http://meincmagazine.com/civis/viewtopic.php?p=28158387#p28158387:fah6sp17 said:sanpinn[/url]":fah6sp17]"A technical issue has occurred on web05."
Sites from the same owner, Condé Nast Digital. Sites which actually are a nice waste of time while engineers reanimate web05. Assuming something was wrong with web05.[url=http://meincmagazine.com/civis/viewtopic.php?p=28158387#p28158387:i0opdx0n said:sanpinn[/url]":i0opdx0n]
arstechnica would refer their users to other websites.
[url=http://meincmagazine.com/civis/viewtopic.php?p=28150729#p28150729:11f000fw said:pythagoreanmetronome[/url]":11f000fw]My Windows 8.1 password to just log into the desktop is now this 11 character random string that I am always like WTF!!!! It's just annoying to use networked devices now.
[url=http://meincmagazine.com/civis/viewtopic.php?p=28151783#p28151783:ab6jzzka said:WpgGuy[/url]":ab6jzzka]On arm chair criticism, you guys are over-sensitive and it comes across as hypocrisy.
Seeing a journalist, reporter or columnist complain about arm chair critics is a bit like seeing police complain about arm chair critics.
These two groups of people earn their livings largely by second-guessing and arm chair critiquing what other people are doing, in both cases often doing under pressure.
Articles on politics, hardware, software, pretty much anything written by someone who isn't actually in the field doing it under commercial and organizational pressure themselves, its all arm chair criticism when its done by journalists, reporters or or columnists.
And that another thing, it is one thing to be able to create something in a slow paced simple academic setting, but in a commercial or government environment one has all these other factors that even individual researchers working in the field, but on their own, have no first hand expertise on.
If you can't your own handle arm chair critics you shouldn't be working for an outfit that earns most of its living by armchair critiquing others.
But we all do arm chair criticism. You do. We do.
Changing occupations from journalism to something else would merely mean doing less of it. You'd be an occasional amateur armchair critic rather than a full-time professional arm chair critic.
So lighten up.
[url=http://meincmagazine.com/civis/viewtopic.php?p=28157505#p28157505:39mwxg0w said:Rainbird[/url]":39mwxg0w]You did get an e-mail.[url=http://meincmagazine.com/civis/viewtopic.php?p=28157425#p28157425:39mwxg0w said:sraboy[/url]":39mwxg0w]Maybe it's just me, but I'd appreciate it if a notice about the breach were posted at the top of the front page, or if I got an email.
[url=http://meincmagazine.com/civis/viewtopic.php?p=28157527#p28157527:39mwxg0w said:epixoip[/url]":39mwxg0w][url=http://meincmagazine.com/civis/viewtopic.php?p=28157505#p28157505:39mwxg0w said:Rainbird[/url]":39mwxg0w]You did get an e-mail.[url=http://meincmagazine.com/civis/viewtopic.php?p=28157425#p28157425:39mwxg0w said:sraboy[/url]":39mwxg0w]Maybe it's just me, but I'd appreciate it if a notice about the breach were posted at the top of the front page, or if I got an email.
And it was at the top of the page for a day and a half.
Then you'd better check to see what's wrong with your email account, because they sent an email notification:[url=http://meincmagazine.com/civis/viewtopic.php?p=28160133#p28160133:3sq7veck said:sraboy[/url]":3sq7veck]No, I did not. My email address is correct and it wasn't caught up in Gmail's spam filter.
Ars Technica was hacked: Please change your password
Ars Technica via mail207.atl101.mcdlv.net
Dec 17 (2 days ago)
to andara
You are receiving this email because you may have - at some point - registered as a user on ArsTechnica.com. Our site was recently hacked.
Log files suggest that this intruder had the opportunity to copy the user database. This database contains no payment information on Ars subscribers, but it does contain user e-mail addresses cryptographically-protected passwords.
Out of an excess of caution, we strongly encourage all Ars readers — especially any who have reused their Ars passwords on other, more sensitive sites — to change their passwords today.
Read more about the incident here: http://meincmagazine.com/staff/2014/12/ar ... t-we-know/
Please login to Ars and update your password or use the "Forgot your password" form to change your password.
Settings page: https://meincmagazine.com/civis/ucp.php?i ... eg_details
Forgot your password? https://meincmagazine.com/civis/ucp.php?mode=sendpassword
We sincerely apologize for any inconvenience this has caused.
- Ars
==============================================
==============================================
Unsubscribe [email address redacted] from this list:
http://arstechnica.us1.list-manage.com/ ... a0d1991c65
[url=http://meincmagazine.com/civis/viewtopic.php?p=28160831#p28160831:25dj885s said:Zanthexter[/url]":25dj885s](LastPass is great)
[url=http://meincmagazine.com/civis/viewtopic.php?p=28161313#p28161313:zaxo5pyr said:MattM[/url]":zaxo5pyr][url=http://meincmagazine.com/civis/viewtopic.php?p=28160831#p28160831:zaxo5pyr said:Zanthexter[/url]":zaxo5pyr](LastPass is great)
i keep hearing about this
what is this?
I keep hearing this, but none of you ever explain why you're just giving out the same, precious email address to every site you register with. Your ability to punch at "novice" users for their password habits ends where your email habits begin.[url=http://meincmagazine.com/civis/viewtopic.php?p=28160831#p28160831:z1mx8pg4 said:Zanthexter[/url]":z1mx8pg4]What I do care about is my email address now being available to be spammed and phished. Possibly my other personal information was associated with my email address and taken as well, to be combined with stolen info from other sites, and a nice hacker/NSA database compiled. To me this is a MUCH bigger issue than a password that can be changed in 5 minutes because I can't ever get back that other information.
It's your data, so you also should take some personal responsibility for safeguarding it whenever possible. For email, that means using something like a disposable address for web site registrations. Those of us who did that with Ars will *know* if spammers ever start using those email addresses; no premature offense necessary.If you aren't protecting ALL of my data, you're doing it wrong!
[url=http://meincmagazine.com/civis/viewtopic.php?p=28152631#p28152631:3ln8d19v said:Jim Z[/url]":3ln8d19v][url=http://meincmagazine.com/civis/viewtopic.php?p=28150225#p28150225:3ln8d19v said:404[/url]":3ln8d19v]Between this and Ars manufactured gamergate garbage which has lead to nothing more than racism and bigotry against minority gamers in favor of a female oppression false flag. All i want to know is, How do i delete my account from this cesspool?
1) you can't.
2) leave anyway, please.
[url=http://meincmagazine.com/civis/viewtopic.php?p=28160653#p28160653:3s37d3fz said:Andara[/url]":3s37d3fz]Then you'd better check to see what's wrong with your email account, because they sent an email notification:[url=http://meincmagazine.com/civis/viewtopic.php?p=28160133#p28160133:3s37d3fz said:sraboy[/url]":3s37d3fz]No, I did not. My email address is correct and it wasn't caught up in Gmail's spam filter.
Ars Technica was hacked: Please change your password
Ars Technica via mail207.atl101.mcdlv.net
Dec 17 (2 days ago)
to andara
You are receiving this email because you may have - at some point - registered as a user on ArsTechnica.com. Our site was recently hacked.
Log files suggest that this intruder had the opportunity to copy the user database. This database contains no payment information on Ars subscribers, but it does contain user e-mail addresses cryptographically-protected passwords.
Out of an excess of caution, we strongly encourage all Ars readers — especially any who have reused their Ars passwords on other, more sensitive sites — to change their passwords today.
Read more about the incident here: http://meincmagazine.com/staff/2014/12/ar ... t-we-know/
Please login to Ars and update your password or use the "Forgot your password" form to change your password.
Settings page: https://meincmagazine.com/civis/ucp.php?i ... eg_details
Forgot your password? https://meincmagazine.com/civis/ucp.php?mode=sendpassword
We sincerely apologize for any inconvenience this has caused.
- Ars
==============================================
==============================================
Unsubscribe [email address redacted] from this list:
http://arstechnica.us1.list-manage.com/ ... a0d1991c65
[url=http://meincmagazine.com/civis/viewtopic.php?p=28150729#p28150729:uuvjy1ol said:pythagoreanmetronome[/url]":uuvjy1ol]Good lord. This year alone I have had all of my debit cards/credit cards canceled and resent to me by my bank TWICE because of Target and Home Depot, which of course has required that I type in new numbers into tons of various websites and payments... online bills, google play, Ventra for Public Transportation, Digital Ocean, AWS etc etc... and this whole password thing. Ars isn't the only one. I use Last Pass now and even that has turned into such a hassle because any app I want to use on my phone or tablet requires at least two steps of authentication IF the lastpass password is actually synced. My Windows 8.1 password to just log into the desktop is now this 11 character random string that I am always like WTF!!!! It's just annoying to use networked devices now.
What can you do? The internet seemed like a good idea there for about 3 weeks in 1994 and after that it has been a steady stream of disgusting porn, trolls, hacks and a thousand little inconveniences. I am about to go unibomber on this shit.
I kid. Thanks for letting me know. Luckily after the whole Ars thread about how the Dred Pirate Roberts had his silkroad passwords set to his cat's name I learned that I should always have TWO cats and kill one on monthly basis. So I am pretty sure I am hack proof on this one. I just got a new kitten last weekend and his name is id_rsa.pub. Hack THAT! Wait. Crap.
[url=http://meincmagazine.com/civis/viewtopic.php?p=28166687#p28166687:3gsgjaja said:foxyshadis[/url]":3gsgjaja]I was just on another website changing some information, when I saw something that really hit me: The real problem isn't passwords, or emails, it's security questions. Not related to the Ars breach, but on websites that have questions, your private life and your security on any other site that uses them can be instantly breached, with no need to reverse any hashes at all. That's where people should be directing their concern and ire, not over the particulars of strength of a fairly secure password hash on a small site -- in the wake of previous breaches that led to millions of password releases already.
I'm not even remotely worried about my Ars password. I changed most everything to a random per-site pass after the Gawker hack (I admit that one woke me up, when I saw my old "throwaway" password in there), and changed everything again to something even stronger after the Adobe breach, but at this point I don't feel there's any point in doing so. By the time they crack my password, I'll have changed it anyway as part of my every-few-years updates, as if anyone wants this account anyway.
It is off topic regardless of validity.[url=http://meincmagazine.com/civis/viewtopic.php?p=28166179#p28166179:7x717s6s said:404[/url]":7x717s6s]Calling reporters out on the racist movement they created is now considered trolling. That's a new one.
[url=http://meincmagazine.com/civis/viewtopic.php?p=28166175#p28166175:1tgkvxyx said:sraboy[/url]":1tgkvxyx][url=http://meincmagazine.com/civis/viewtopic.php?p=28160653#p28160653:1tgkvxyx said:Andara[/url]":1tgkvxyx]Then you'd better check to see what's wrong with your email account, because they sent an email notification:[url=http://meincmagazine.com/civis/viewtopic.php?p=28160133#p28160133:1tgkvxyx said:sraboy[/url]":1tgkvxyx]No, I did not. My email address is correct and it wasn't caught up in Gmail's spam filter.
Ars Technica was hacked: Please change your password
Ars Technica via mail207.atl101.mcdlv.net
Dec 17 (2 days ago)
to andara
You are receiving this email because you may have - at some point - registered as a user on ArsTechnica.com. Our site was recently hacked.
Log files suggest that this intruder had the opportunity to copy the user database. This database contains no payment information on Ars subscribers, but it does contain user e-mail addresses cryptographically-protected passwords.
Out of an excess of caution, we strongly encourage all Ars readers — especially any who have reused their Ars passwords on other, more sensitive sites — to change their passwords today.
Read more about the incident here: http://meincmagazine.com/staff/2014/12/ar ... t-we-know/
Please login to Ars and update your password or use the "Forgot your password" form to change your password.
Settings page: https://meincmagazine.com/civis/ucp.php?i ... eg_details
Forgot your password? https://meincmagazine.com/civis/ucp.php?mode=sendpassword
We sincerely apologize for any inconvenience this has caused.
- Ars
==============================================
==============================================
Unsubscribe [email address redacted] from this list:
http://arstechnica.us1.list-manage.com/ ... a0d1991c65
Yeah, still nothing. It's Gmail, plain old standard web-interface Gmail. No filters or anything other than the defaults. The only thing I can think of is that I've opted out of Ars emails but I've never seen an opt-out apply to security issues, plus I still get all these topic replies from the forums so it's not a domain-wide opt-out.
[url=http://meincmagazine.com/civis/viewtopic.php?p=28176819#p28176819:3kph6tz6 said:stevesether[/url]":3kph6tz6]@epixoip
I think your defense of MD5 as a password hashing mechanism are a bit strong. MD5 has been "broken", in that trivial collisions have been found with a very small complexity and minimal processing power.