65M Tumblr Passwords for Sale on TheRealDeal
electronic-sushi.tumblr.com
electronic-sushi.tumblr.com
As an industry, I think we need to rethink the way we develop, package, and deploy web apps. The fact that we rely on individual developers and sysadmins to get security right, perfectly, every time is crazy. In an ideal world the prod environment should protect me from shooting myself in the foot, and the OS should be running a hardened-by-default, single-purpose system image that doesn't require bespoke knowledge to make secure.
While far from perfect, I think the PaaS vendors (AppEngine and Heroku) got a lot of things right in this regard. [Disclaimer: I work for Google, but not on Google Cloud.]
But some of the password hashing algos used, no salting, making all password characters lower-case in the background, etc. are not hard things to avoid. So when a site is hacked and the user information stolen and we find that stuff out, it's safer to assume other security practices where also subpar.
A few years after I left, their DB was compromised, so someone got a list of email addresses with clear text passwords.
Knowing who leaked your email or sold it to spammers
Being able to stop spam by deleting the email
You could even consider binding the email to a domain so the address would only accept emails from the domain you gave this email address.
You don't really want different mailboxes, you want one mailbox with different aliases. An alias becomes a "communication token" which can be revoked, very much like when paypal gives a payment authorisation token to an ecommerce website. If that token gets leaked, no big deal, no one else can use it. A single email address is more like a credit card number.
The per_site_suffix can be anything you want.
So when my email gets reissued i'll have to track down every single website it's linked to and purge any personal information etc. Fantastic.
Out of curiosity, what do the usernames (aka local part) of the e-mail addresses look like? Are they based on names/initials? Are they arbitrary?
My high school followed a similar structure, but had the graduating year as a suffix, implying that they would never be reused.
I wouldn't be surprised if this was rampant in educational institutions who have to provision emails to people with identical names all the time.
(those addresses are mine, first the generic ID, then the generic ID [at] faculty, then prefix [at] generic (I don’t have one), then prefix [at] faculty; first comes first serve on prefixes)
I'm not sure what to make of that information, since I know it's not a recycled email address.
For example, D&D Online and Heroes of Newerth both were compromised.
Here's my question...what recourse is there beyond resetting passwords? If a company did something as dumb as store my PW in plaintext, do I have any realistic legal recourse for what seems pretty negligent? I'd assume I'd have to prove damages of some sort, and I am not a fan of an overly litigious society, but it seems there is no real recourse for impacted users.
http://www.businesswire.com/news/home/20160531005770/en/Time...
I've taken to doing the thing they tell you never to do: I write my passwords down on a piece of paper. Criminals can get access to my passwords, but they're going to have to travel to my house to do it.
It appears some random words aren't necessarily random. Words like 'shadow' and '1q2w3e4r'.
Fascinating!
password => p455w0rd
password => passw0rd- HaveIBeenPwnd contains the data on sale here
I've changed my Tumblr password after this just in case, but it was some approximately hundred character random password generated by Lastpass before that.
So let's say half the ASCII range, which gives us this number of possible passwords:
(2^7/2)^100
41495155688809929585124078636911611510124462322424368999956573296906\
52811412908146399707048947103794288197886611300789182395151075411775\
307886874834113963687061181803401509523685376.00000000000000000000
I'm pretty sure even if it's just stored as single-iteration sha1() cracking it would take until the heat death of the universe.Still, the hash time for a SHA1 is fairly insignificant at this point.
It's much better than plaintext, but essentially only a little bit better than unsalted MD5.
I'm really surprised Tumblr would use such an awful password storage scheme as late as 2013. I thought they invested a lot into security?
I consider precomputed attacks a special case of these attacks, sort of. In the security world, most password-predicting attacks are linear with respect to the amount of accounts you're trying to get passwords for.
It's true that it will take a lot of hardware to efficiently attack all 65 million passwords. But in my field, big dumps like these are a godsend when doing a pentest.
Looking to compromise a sysadmin's account? Search his/her emails and aliases in as many DB dumps as you can find, then expend a lot of resources cracking that one hash. If it's just a SHA-1 hash and the password isn't very strong, you won't have much trouble.
Also a risk for people with vendettas against specific tumblr users (which, to my understanding, is a big issue on tumblr).
At least one major benefit of SHA over MD5 is that you won't trivially find collisions and thus compromise the accounts of even those users with strong passwords...
People downplay the probability and importance of these issues, but the situations where you loose your phone are often the situations where you need access to your online accounts. One such situation can do far more damage than all the hacks combined. (For example, someone steals your backpack with your phone and wallet. Horror scenario: someone steals your backpack with your phone and wallet in a foreign country.)
In short, loss of access must be considered as a tradeoff.
Loosing anonymity due to phone-based 2FA is another issue that never seems to be considered in these discussions.
Finally, phone-based 2FA discourages you from splitting your accounts. (It's a bit of a hassle even with one email. Imagine managing 5 or 6.)
Not sure how anonymity factors in here. How can typing a number into your phone to set up TOTP then typing the resulting numbers back into your already-authenticated account deanonymize you?
Finally, yes, adding more security is a hassle. But if you're willing to add 5 seconds to your login on one account, I don't see why you'd be super against doing that for multiple accounts.