Top 250 cracked Gawker passwords
duosecurity.com
duosecurity.com
If i want to post a comment on a lifehacker blog post, there is a decent chance that i give some random string and 123456 as the username and password. This is the case when i know that i won't be using it again. True that an email is associated with the login credentials but still this might be true for many of those passwords.
I am curious is there a particular reason behind the fact that 70 people choosed that number for their password?
This number seems completely random to me so I dont understand the how and the why.
I felt pretty good after that. Why I can't tell you but I did.
If you still don't know, try searching for it on this wonderful resource: http://oeis.org/
I saw this one and at first I thought it would be a good password. Then I realized the pattern on the keyboard. I was thinking the other day, would there be any need to make a password crack program that focused more on patterns on the keyboard instead of vocabulary. xlsow02 uses the ring finger on each hand to type out what should score a strong rating on most password checkers yet is a simple human pattern for easy memorization.
Anyone have experiences integrating libcrack into their web app? I hesitate to integrate it because it would cause potential clients to quit the signup.
Alternatively, I think this list would be invaluable as a smaller blacklist. Thanks!
As to integrating libcrack in your signup process: if an account at your site isn't actually important, I'm sad to say that you probably shouldn't bother. People who reuse passwords are, sadly, at much more risk from the other sites (if you're even aware of libcrack, you're well ahead of the curve); and a password like 'password' isn't all that bad for something as value-less as gawker.
Who self identifies with that horrible term so closely that they would use it as their password?
A lot more people than I thought evidently.
I had forgotten that part of the whole sorry story. Reminds me of the uni I attended, (Sussex) where not only were passwords truncated, there was in fact a max length policy of 8 chars. This was across their entire campus network, and all intranet apps. Yeah, my degree ain't worth much.
Can anyone with more experience point out whether I am in any way on the right track here?
EDIT: hmmm, the storage of the passwords as 8-char weak hashes would render the more secure hash function used on the modern systems irrelevant. Maybe use the output of the strong hash as the input of the weak hash? Would this be secure?
Thank god the safe best-practices are clear and simple in the majority of cases.
EDIT: in case anyone reading this is wondering, the safe best-practice is to USE BCRYPT.
I don't want to get paranoïd and I see no point in changing my password to minor services unless there is a really good chance that it got compromized.
The "strong" versus "weak" message that some password checking services provide tells me nothing very usefull because what is weak when you focus a cluster of CPU for a week on may be "strong" for those who use the Gawker leak and don't have (I guess) such ressources.
by using different passwords in each site ?
you can't be sure, it's just a matter of time and desire, I have the time and resources, for instance, but no desire.
124 swordfis
108 spiderma
98 chocolat
90 elizabet
88 butterfl
79 basketba
(among others)Why would anyone put a limit -- especially such a short one -- on password length? Please don't tell me it's because they want to store them as char(8).
For instance, our #4 was lifehack with 861 results. We also came up with different counts.
It is probably worth comparing our methodologies and results: http://intrepidusgroup.com/insight/2010/12/gawker-des-crypt-... if you are interested in this.
edit: Amusingly, lifehack was the only password in our top100 missing from the linked top250. Given more time I am assuming lifehack would have dropped out during Duo's crack as a popular password since it is 8 characters and lower case.
Jeremy
-"starwars": 256; "startrek": 88
-"sunshine" barely beat out "shadow" 266-255
-"trustno1": 307 was pretty surprising (it's a reference to the x-files)
-"superman": 297; "batman": 159; "spiderma": 108
I realize asking this also is asking for an instruction manual for malice with whatever is decrypted. I just don't know how to determine how exposed my email address leaves me.
If you'd like, email me and I can try to retrieve your password hash based on your email address. My email is in my profile.
It's one of the top 10 passwords on that list.