Mark Zuckerberg's Twitter and Pinterest password was 'dadada'
theregister.co.uk
theregister.co.uk
I do remember in middle school (a religious one) a classmate got in trouble (detention?) for loudly wondering if the Biology teacher and softball coach in her 30s with short hair and drove an Isuzu Rodeo might be a lesbian.
Sounds about right.
Because, generally username/password remains the least-bad primary method we have for most uses, and most other methods work best as secondary methods with that rather than replacements.
> It's not like we don't have better technology.
Yes, it is.
> Why can't I just authenticate everywhere with a signed token?
Because, unless they are accompanied by (or secured on the user end by) passwords, signing keys that enable that are more prone to theft, whether by copying (if they aren't kept in a hardware device designed to prevent that) or by theft of the device they are in.
Which is why that mechanism is usually used as a second-factor with passwords for systems needing additional security, rather than a replacement for passwords.
EDIT: I'm not saying passwords are ideal, just giving context as to why they haven't been replaced.
All I need to login from any device in the world is my password. As soon as you introduce tokens or private keys or whatever you need something to securely store that, most likely protected by... a password.
I can imagine some crazy implant + biometric authentication scheme but we're a long ways off from that sort of thing being universally accepted.
People lose things, steal things, etc. but you cannot (as of yet) steal someone's thoughts.
I have a feeling that today things are better than that, but who knows, maybe not.
The passwords were hashed with SHA1, not encrypted.
For example someone else may have had dadada as a password and isuckat@passwords.com as their email, and their password was discovered via a separate breach on some other site. That other site used shit technology for securing people's passwords. isuckat@passwords.com was in the linkedin dump.
People can probably guess that any hash for isuckat@passwords.com will probably be 'dadada'. Now based on this information figuring out the hash for other users also using 'dadada' as their password is simpler. Multiply by many thousands of people reusing the same stupid password on all their sites.
In other words use a unique password and use a different unique password for each site and service you use. Use a password manager.
What if the salt was derived from a key the user had to supply and wasn't stored anywhere?
Modern state of the art for targeted attacks is to use slow hash algorithms, such as bcrypt. They have little effect on normal operations, as most users will get the right password within a few tries, so you're adding a negligible amount of time per user. But the extra time has a huge effect when an attacker is trying to calculate millions of hashes for a single user.
If I understood you that is the same as demanding the user to input two strings for password authentication, one for salt and one for password, in which case you might just as well require the user to use a longer password.
Since most people walk around with their cellphones, you could even precompute a couple keys to unlock a site, for those times when there is no internet connection. Of course, your phone should be secured with a password and you should be able to revoke the keys if anything gets lost.
Disclaimer: this is personal observation.