RockYou.com database breached, 32 million unencrypted passwords obtained
rockyou.com
rockyou.com
Our users' privacy and data security have always been
a priority for RockYou and we strive to keep them secure
No you don'tHe seems to be on a crusade against bad security practices - RockYou was just one out of many sites he hacked (other sites are mostly Czech and Slovak).
Here in Slovakia, it's almost weekly media event when he hacks yet another popular local site (mobile phone operator, insurance company, no.1 portal, etc).
He also likes to call bullshit on companies PR nonsense released in aftermath.
Pandora Radio, for instance.
salt+[reversed first four letters of site name]+[number of digits in site name] not the actual rule I used, but you get the idea
That was okay, but kind of annoying. Plus, I figured that the rule wouldn't be overly difficult to break, and then I'd be just as screwed as if I used the same PW for all sites.
Now I use 1Password to generate and store all of my passwords. I use dropbox to sync it across all my computers, and if I log in to dropbox, I can access a web interface. There's also an iPhone app, so it's not completely annoying never knowing any of my passwords, and I don't have to worry about one site storing my PW plain text and being exploited. [Now I just need to worry about my dropbox account getting hacked... here's hoping they don't store in plain text ;)]
I don't have anything to do with 1Password, and there are a lot of other apps out there that do the same thing.
When I first learned about databases, that is the very first thing I learned never to do.
Of course, once Facebook et all started using OAuth-like protocols they should have dropped the passwords. There's a lot of shame here for sure, but its not quite as amateur of a mistake as it sounds on first blush.
"This matter now appears worse than originally suspected as the dataset also contains a table where RockYou have stored user credentials for social networks and other partner sites."
http://www.techcrunch.com/2009/12/14/rockyou-hack-security-m...
Also, consider RockYou's initial statement, in which they would only say that no Facebook accounts were compromised:
"RockYou confirms that no application accounts on Facebook were impacted by this hack and that most of the accounts affected were for earlier applications (including slideshow, glitter text, fun notes) that are no longer formally supported by the company."
But you're right about them storing the internal passwords in clear text, which I did not know. That is absurdly dumb.
To me, this is a textbook case of a non-apology apology. Allowing (unencrypted!) passwords to be stolen isn't inconvenient to users, it's a pain in the ass.
I love the fact that they mention multiple times that it was an illegal breach as if that diminishes their culpability.
Next we're going to find out that their system accepts the username "Delete from users WHERE"...
There should be a list of companies/sites that don't encrypt passwords, so we know what services to avoid. That way, next time you use the Forgot Your Password feature and they email you your plaintext password, you can add them to the list to warn others.
If the passwords are just encrypted, once the attacker figures out the algorithm, then all of the passwords will be compromised. A hash, on the other hand, would require each account password to be broken individually.
Hi, I'm interested in your opening for Engineering Lead for Social Applications.
I made a PHP page as a high school project that let me log in and create blog posts. I required an admin account to log into the blog to write articles. My user table (I used MySQL as a database backend), had four columns: id, email, username, password. It sounds very simple, but please let me tell you some of the special technology I used for the password.
If someone used a password of "password", I would do something like this:
$plaintext = "password";
Then, I would use a function called sha1 to get a a new value of the password like this: $salt = sha1(md5($plaintext));
Then, I would get the final value to store as the password like so: $password = $md5($salt.$plaintext);
This way, the password is hidden behind what people call a hashing algorithm. That keeps people from figuring out the original password, even if they somehow got on my computer!
I know I have no professional programming experience, but I think that I could be a very valuable member of your team. If you're interested, please let me know!
-Scott
http://gigaom.com/2009/12/30/rockyou-sued-over-user-data-bre...
I really wish they would implement a feature that lists similar topics when you are about to submit a new one.