Should I Change My Password?
shouldichangemypassword.com
shouldichangemypassword.com
<html> <body> <h1>YES</h1> </body> </html>
<h1>YES <!DOCTYPE html>
<title>YES</title>
<h1>YES</h1>http://validator.w3.org/check?uri=http%3A%2F%2Funitinu.net%2...
http://validator.w3.org/check?uri=http%3A%2F%2Funitinu.net%2...
http://validator.w3.org/check?uri=http%3A%2F%2Funitinu.net%2...
Dang, apparently so. Guess I was wrong.
The world's most inane objection: If you force the validator to HTML5 mode, (as in the first and second links) then you don't need to declare a DOCTYPE, a savings of 16 bytes. Not that you would ever do that for a real document, since it's a dumb idea.
And if it does, the page will be updated to "Yes.", right?
if (!(typeof worldHasEnded == "undefined")) {
document.write("YUP.");
} else {
document.write("NOPE.");
}
And, it even comes with a warranty:> <!-- if the lhc actually destroys the earth & this page isn't yet updated please email mike@frantic.org to receive a full refund -->
Something like that you mean?
To enable this - you are giving your email, password, Payment details and Cell Phone number. The site as it stands today doesn't ask for any of this -- but if they were to take payments and do SMS notification they would.
From the lighttpd logs, 842 POST requests for 1834 GET requests from distinct IP adresses (and 1424/5896 overall), but we don't keep logs so I can't know what people submitted, I guess a good part of it is random typing and not really their password.
BTW, the fun is also (if not mainly) in the Terms and Conditions ;-).
Oh, and I host it, but the creator is a3_nm.
For instance, apparently billg@microsoft.com should change his or her password, according to the site.
Why did I not enter an e-mail address like the light text in the input box says? Well, I let myself mislead by the header image.
I think not!
Anyway, I tried "abc124" and received: "It looks like your passwords may be safe. No instances of compromise are recorded in this database. However, it's good practice to change your critical passwords regularly and ensure they are not re-used across multiple sites."
Yes, I would be disturbed if a public site was reversing weak poor choices in hash algorithm and publishing data about the resulting passwords.
The only defense I can offer is that the name, introduction and the feedback text (which should at least check for "@") is kind off or misleading.
Anyway, my fault, I apologize to the web site creator.
Please try it in your replies.
you might think that the phone number of that cute girl in that movie combined with her initials is a safe password, but if you check out some of the password lists that have popped up the last year you'll see that alot of people thought the same way.
That said, really useful service. On the other hand it's sad that we actually need something like this.
Granted, the average user doesn't need to know or understand the vagaries of password hashes. But if somebody reads this, they should think "OMFG somebody can login to my email account!" I mean, that's exactly what it says. But there's no legitimate reason to believe that.
Moreover, if you look at MtGox, Google locked every account on that list and forced people to change their passwords. But if you're Joe User looking at this today, are you going to connect the dots enough to see that yes, you WERE in a data leak, but then you changed your password, but this site just didn't know about it and is informing you only of the leak?
If you have specific suggestions, I would be happy to discuss them.
Plenty of sites still store an unsalted hash in the database and these are often compromised.
If your hash turns up in a rainbow table in Google's index, definitely change it to something more secure (longer, more symbols).
(Yes, I know that sniffing such things is not trivial. Still.)
If you are persistent with testing your password hash you risk making that hash public.
If you've entered your real password(s) there, you've already failed the test.
Also a whois on that domain doesn't even return a person's information, some proxied info only (might be scared of law enforcement since he might have the hacked DB data, but even so, if I didn't trust it, I trust it even less now).
ShouldIChange site reports no instances of compromised records in it's db.
It's checking the e-mails on those databases.
If you're asking, then YES. You should change your password.
Edit: I get what this is doing, and it's a neat idea... But the answer is still always YES if you ask that question.
I have a personal domain on google apps. The login ID is different than the email address I use/advertise.
e.g. my username for login is first-initial+last-name@[domain].com
But the email address I use for everything on that account is first-name@[domain].com
This service states that my account was compromised on 12/12/2010 most recently at the first-name@[domain].com though you could not login to my account with that email address...
So - how valid is such a check. Also - without it showing what information it is checking against, it feels really spammy. as if they are asking you to enter your email for a "check" knowing that you will enter a valid email - then they harvest the email as valid for spam.
It should tell you which sites were compromised such that you can ID if you used your email at any of said sites.
Just saying ambiguously that there was a site which may have been compromised out of the 2 billion sites online is laughable.
In fact, I would say that prompting the average person to change some passwords either way, is a good thing.
To me this means that my password is out there, and now a part of someone's dictionary. Change all places where that password is used immediately. I am currently moving to LastPass with randomly generated 16-32 char passwords for every site. It's less of a pain than one might think.
It says it's using the perlmonks.org database, and I _know_ my password was revealed there (thanks to me foolishly reusing it on twitter), but it's not showing that against my email address...