Millions of stolen Last.fm passwords have been decrypted. These are the top 50
qz.com
qz.com
The best thing I ever did for my parents was teach them to use different passwords everywhere. Against conventional wisdom, I get them to write them down in a book, because for them, keeping a book secure is much easier than knowing what to do to keep their computers secure. We already know how to keep physical objects reasonably secure, we do it every day with our credit cards, passports, jewelry etc.
Worse yet, some such sites intentionally break pasting into the password field, making it a pain to paste in a randomly generated password.
You can fix that with a bookmarklet to re-enable pasting.
var inputs = document.getElementsByTagName('input');
for (var i=0; i < inputs.length; i++) {
if (inputs[i].getAttribute('type').toLowerCase() === 'password') {
inputs[i].setAttribute('onpaste', '');
}
}
(Tested with desktop Safari, no idea about other browsers.)Even if we get better at this, the top passwords will still be these, they'll just be lower as a % of the total. So until we have 100% unique passwords, this story will always be there, which just seems lazy.
Passwords were stored using unsalted MD5 hashing.
It's 2016... why is this still happening?I may never see the sunlight again.