Gawker Website source, databases & passwords now on BitTorrent
thepiratebay.org
thepiratebay.org
Remember, don’t use the same password across the Internet. Here’s why.
Edit: It’s there, apparently as a DES hash. …
Update 2: The first two characters are the hash. So if you use a tool like https://hash.online-convert.com/des-generator you are going to put your password in the “Text you want to convert…” box and the first two characters of your hashed password in as the “Salt (optional)”. Then you will see the “Calculated DES Hash” which will be the same as the hashed password from the torrent if you knew or guessed the password correctly.
E.g.
Your Lifehacker password is “hackern”, but in the torrent, it’s just “8h48GPxmwy.EA”. Just to show the torrent is legit, you go to the website I entered above, enter “hackern” and “8h” as the salt; it will spit back “8h48GPxmwy.EA”.
Update 3: “OFFER HN”: The most paltry “Offer HN” ever — send me your username or email address and I’ll grep both files for you to see if your password and/or hash is in one of them. My email is contact-at-<HN username>ogan.com
Personally if someone would mail me warning me some site that I am a member of has been compromised I would thank the guy.
Gawker probably will not see it that way, but since these email addresses are going to be spammed to death anyway I would think that's a minor issue.
Go to gawker.com and use the 'forgot my password' utility. It's under login > forgot my password. Enter your email address in the field provided. It will tell you straight away "That email address is not in our records. Please try again."
I can't think of any reason this would be incorrect based on the recent events. Of course, this doesn't tell you whether your password is vulnerable, just whether you have an account.
Hi there,
Hint wanted to let you know that your email address and password that you used to signup for Gawker (or one of its sites) were hacked. Forbes' coverage is here
In situations like this, time is of the essence, which is why we were surprised & shocked to find that Gawker Media hadn't taken the initiative to notify you of this privacy breach immediately. We HIGHLY recommend you change all of your online passwords as a precaution.
-The Team at Hint
(This is a one time email)
I'm not sure how ethical this is.
I'm sure you can imagine the worst that could happen. Courtrooms are not happy fun places.
It's the one starting with 7335e7777f449de7533bfcc81efda
For the past 2 years I have been ashing all my password with custom algorithms in a hashing bookmarklet but I don't even remember when or why I created an account on there and I am curious on which password I've used.
Here's a version without: http://undertow.jedsmith.org/gawker/
I manage a domain through Google Apps, and I've discovered that that domain is on the list.
It's probably me, but I can't figure out what address was used (none of the md5 hashes are matching that are in the fusion table).
Seeing as you've got this for analysis, it'd be nice if you could help me figure out if one of my users was compromised (the domain is the same as the email on my hn profile).
It'd really suck if I have to change my password scheme because of this. :|
I definitely don't do this.
If the servers are still compromised, I don't think they'd have stopped with a dump full of hashes and a few posts on Gawker. My guess is that the intrusion was discovered while they were doing the dump, which is why it's incomplete.
(Much more anonymous than the Google document somebody pasted below. Seriously? Domains?)
Firefox: https://www.pwdhash.com/ Chrome: https://chrome.google.com/extensions/search?itemlang=&hl...
grep -o '[[:alnum:]+\.\_\-]*@[[:alnum:]+\.\_\-]*' yahoo_ab.csv | while read line; do grep " $line" parsed_db.txt; done
For those not in the know, you can export a CSV of your Facebook friends' email addresses in under 4 minutes by following this guide: http://lifehacker.com/5690378/how-to-export-your-friends-ema...
which yields a yahoo_ab.csv. From there you can cross check it against the parsed_db.txt file or the full_db.logYou should probably tell your friends if they're showing up in the parsed_db.txt as one of their passwords can now be seen by anyone.
ruby -e 'puts "hackern".crypt("8h")' #=> 8h48GPxmwy.EA
1) fire up terminal on your local macbook and enter the above string subbing in your password
2) open the spreadsheet and set the filters to domain - enter your domain name(s) and hit submit
3) If any results are returned then compare the MD5 hash in the result set with the MD5 hash returned from step #. if they're the same, start changing your passwords.
We have the list. Anyone with a MailChimp account want to be a good samaritan?
Edit: I'll certainly help, but I and my girlfriend, Stella Artois, have been lamenting the embarrassing loss our Jets suffered this evening, so I figured I'd float the idea for vetting first :)
Edit 2: Wow: I know a lot of people on this list. I'm letting them know, and recommend that others scan on behalf of friends and family as well. I've been told that there has not been active communication; wish gawker would confirm either way.
A quick search shows staff email addresses at techcrunch, apple, microsoft, google, goldman sachs, etc.
http://www.securityweek.com/study-reveals-75-percent-individ...
So, uh, how come I and everyone else affected don't have an email in our inboxes from Gawker right now, marked as urgent, explaining the situation?
Doesn't that seem like the right thing to do?
http://www.ilxor.com/ILX/ThreadSelectedControllerServlet?sho...
FWIW: I wasn't notified.
javascript:document.cookie='noad=true; expires=Thu, 2 Aug 2021 20:47:11 UTC; path=/';
This shuts everything off, except for one ad at the top.(Put a bookmarklet for this if anyone who wants to try it out: http://bit.ly/exvive)
From Felix Salmon:
Most of the value of Gawker Media lies in Hungary—but how much value is there, really? To a large degree that depends on what Denton decides to do with his proprietary technology. Other blogging platforms are worth nine-figure sums—Tumblr just got a valuation of $135 million, while Automattic, the parent of WordPress, turned down a $200 million acquisition offer three years ago, when it was much smaller than it is today, and subsequently raised money at a valuation north of $150 million. I know a lot of people at big media companies who struggle with the limitations of WordPress, and who would pay good money to license an alternative web publishing technology, if it was robust and proven. Big companies are already licensing the NYT’s Press Engine mobile-publishing technology, and it’s rumored that at one point Denton was talking to Bonnie Fuller about licensing his technology to her nascent website, although that never happened.
Yes, it does. Several copies of it, including trunk.
I'm currently writing a little script that parses all the address and emails the owner a heads up. I gotta step out so I won't have it done for 2-3 hours and I thought I'd post here in case anyone else has that idea (don't want to flood the victims).
Granted, all had different passwords, but people are taking full advantage of this information being made public.
Personally I'm not as worried about Gnosis or 4channers doing anything particularly malicious with the data -- that's not their goal. Their goal is to publish it so other people do malicious things with the data, with all the resulting animosity being directed to Gawker.
It lists a bunch of the password/email combinations (plaintext), and tells a bit about how they did it. I'm guessing they used a dictionary attack for the easy ones. Also displays chat logs from campfire that show the staff in a highly unfavourable light. Then again, their work does that just fine without any outside help.
All the usernames and passwords for users with {@lifehacker.com, @gawker.com, etc.} email addresses in the torrent (plaintext, not hashed). The torrent claims Nick Denton’s password was an 8-character sequence of even numbers, and that he used it everywhere. (Edit in reply: The hackers used this on e.g. his Twitter account IIRC so it wasn’t truncated to 8 characters.) Some of them are even '11223344' or a substring of the author’s username!
That also means that, although unlikely for some, '11223344' could have actually been '11223344aBc$!q'. Not that it would have mattered though!
This is why I freaked out when bluehost.com (AVOID!) required the last four characters of my password to accompany support requests(!).
I don't think I've logged into any of their sites, I use different passwords at different sites and they are generally > 20 chars, so I'm not worried. Yet, at the same time, even knowing all of that, I did a bit of a double take and had a brief "Oh shi-" moment of paranoia when I read the headline.
In fact, if I were say a young starlet that used a similar password for my private email or something as my Gawker account, I'd be really freaked!
One thing open to interpretation would be whether the password in the file could be used to access someone's bank account. If someone uses the same e-mail address and password at both sites, that would be true.
Section 1798.29, E, 3
-- Definition of Personal Information
Account number, credit or debit card number,
in combination with any required security code,
access code, or password that would permit
access to an individual's financial account.
* http://info.sen.ca.gov/pub/01-02/bill/sen/sb_1351-1400/sb_13...I am not a lawyer.
http://www.cs.utexas.edu/users/byoung/cs361/crack-assignment...
It gives a little bit of background information on password hashing and salting, and on simple password cracking techniques.
After all, if 1 password gets hacked the passwords that are generated could be sent to two parties instead of just to you.
And if someone mounts a camera in the smoke detector in my apartment they could see me type in the double super secret password whose plaintext has never been stored by a computer.
So what's your point, exactly? Tools which generate good passwords and store them locally on your computer with decent-enough security are light-years ahead of what most people do, and their use should be encouraged.
But in my experience, too many people confuse "this is a possible threat" with "this is a threat it's reasonable for me worry/take action about", and that's what I was getting at.
1password is easier and a much juicier target, so compromised binaries are definitely a possible threat. How would you know it was compromised, unless you had a packet sniffer going on your network?
It's possible that a password manager could be completely open source, distributed with checksums and public key signatures, that my C compiler could be completely open source and distributed with checksums and public key signatures, and I could still end up with a backdoor in the final compiled result, detectable only by deciding to carefully examine the binary I just built.
This is a "possible threat". Should I use that possibility as a justification for never using a password manager? Or for never using a C compiler?
And it's not just a "possible threat" but a likely one, and it's happened multiple times in the past. Sites get hacked all the time, and trojans are standard practice these days (unlike compromised-binary-generating C compilers):
https://threatpost.com/en_us/blogs/savannah-gnu-site-comprom...
http://www.esecurityplanet.com/trends/article.php/2248811/GN...
https://threatpost.com/en_us/blogs/apache-site-hacked-throug...
What your suggesting is far less complex than the Stuxnet virus. You need to get binaries from reliable source and verify checksums whenever possible. You can't protect yourself a 100%, but that doesn't mean you should leave or your doors unlocked.
I use 1Password, and it sure beats my old strategy of using a text file for all my unimportant passwords.
Coincidentally, the 1Password plugin is helpful in preventing phishing, too. If you're at the wrong site, the 1Password autofill will not work.
Half of my comment actually disappeared when i posted this as well. Had to edit it to get everything in.
This is why my preferred hashing scheme is username + seed + password, so that even if user1 and user2 both use "password" as their password, they'll end up with different hashes. That way if the database is compromised you can't do frequency analysis against the hashes to make guessing common passwords easier.
> bcrypt gets you a future-hardened algorithm that can be adjusted in responses to gains in computing power.
How would I be able to change the cost factor overtime? I don't store my user's passwords. Should I just re-bcrypt the bcrypted password using a higher cost and in my login_verify code, take that into account? Or is there something else you can do overtime to raise the cost factor?
One system I built stores the workfactor used to bcrypt the current password un the user table, and allows me to increase the "system workfactor". Every time someone successfully logs in with a lower-than-current-workfactor password hash, it recomputes a new bcrypted hash using the currently known successful login password and updates the users credentials. It means if my user table is ever exposed, all frequently used accounts have up-to-date workfactors for their password hashes, and the "relatively weaker" hashes are for infrequently used (or, in this particualar case, expired subscriptions).
EDIT: I've also recommended using a random salt for each password too, but this is only a layer of security if you're code is not also stolen, then it is simply a slight additional "slow factor"
You could up the iteration however much is needed (say, 1000, 10,000).
It's poor security countermeasure, but it was a specific scenario :) The general idea is to combine salting and iteration to produce a poor mans slow hash.
(which works great for software you're distributing for use on random shared architecture a la wordpress - just to give an example)
Use Bcrypt where you can.
That's the crux of the problem. Hashes that are good for fingerprinting files (MD5, SHA-n) aren't good for keeping passwords secure, because they need to be fast. Your idea seems fine, but you're forgetting the "first rule of implementing crypto primitives": don't do it! (http://www.letsyouandhimfight.com/2010/07/14/cl-bcrypt-a-fir...)
First off; it is not a primitive, but a protocol, it is still a bad idea to design those yourself. But they are not; they are getting the advice of an expert.
Secondly; this is in a specific scenario where you are left only with the fast digests (shockingly, this is still a common situation). Introducing an "artificial" slow factor is accepted practice.
Thirdly; this is definitely not my idea. The iteration suggestion was from tptacek who months ago answered a similar question to this with something along the lines of "if you must insist on using fast hashing for gods sake iterate it a number of times" (I can't find the quote off hand, it was some time ago, but I entirely agree). The rotating random salt is an old old idea.
It's very easy to recite the mantra "always use bcrypt, follow the first rule of crypto, digests are evil", but it's even harder to use that knowledge in practice, I find. :)
You can introduce slowing factors like seed values and iterations (bcrypt uses both) but they're a bad idea if you're doing it yourself. For example, your initial estimate of 50 iterations is at least a couple of orders of magnitude out. How many is safe? 10,000? 100,000?
BTW, I'd be interested to know exactly what this mythical situation is where you're handling user accounts, but don't have access to one of the existing bycrypt implementations (C, Ruby, Python, PHP) and can't compile your own.
However. Mythical situation? Try a good portion of shared PHP hosting; why do you think the most popular software in the world (i.e. stuff like Wordpress) still supports MD5/Sha hashing?
I realise this is not a problem you may have come across before; but don't imagine it does not exist :)
But really - it's just another reason not to use PHP, and not to have a crappy webhost. You could probably say much the same things about backups, app security, bad UI or design. But for most people, don't do that is apparently not a good enough answer.
Update: Just looking into how Django stores passwords, and it does much the same thing (although it falls back to SHA-1, rather than MD5). There was a push to use bcrypt a while back, but it got marked wontfix, due to "backwards compatibility issues". Sigh.
the search results from google are all added code, but php supports it natively: http://ca.php.net/manual/en/function.crypt.php
Edit: crypt -> bcrypt, stupid iPad autocorrect
Gawker uses a really outdated hashing algorithm known as DES (Data Encryption Standard). Because DES has a maximum of 8 chars using a password like "abcdefgh1234" only the first 8 characters "abcdefgh" are encrypted and stored in the database. If your password is longer than 8 characters you only need to enter the first 8 characters to log in!
Is this true? I tested it now and it needed the full password for a successful login.
I don't know that either, but regardless, I think you should have a look: ThomasPtacek@xxx.com is in there, assuming that's yours.
elptacek is in there as well.
Odd, I'm sure I had a lifehacker comments account, but my username isn't listed. No complaints though.
I must admit I'm a bit intrigued as to why mine's not there. Anyone else in this boat?
After gaining access to gawkers MySQL database we stumble upon a huge
table containing ~1,500,000 users. After a few days of dumping we
decided that 1.3 million was enough."The actual database size is 1,247,897 rows, which is 80+% of their database." - http://www.mediaite.com/online/exclusive-gawker-hacker-gnosi...
I wish I could win a raffle with that sort of luck though! ;)
Kind of ironic really, considering the whole secrecy vs non-secrecy debate.
It's a free account that I got via an AppSumo bundle, so no real loss to me if it gets terminated, but I'd rather not go that route to begin with, ya know?
EDIT: Nevermind - it seems that resetting your password at gawker.com resets for all of their sites.