What do Sony and Yahoo have in common? Passwords
troyhunt.com
troyhunt.com
"This is from a sample size of 302 common accounts and
unsurprisingly, the strength of those passwords leaves
a lot to be desired:"
The word "this" refers to the passwords list after the colon, not the preceding analysis. It really should have been written as "The following list of weak passwords is from a sample size of 302...".Now that all said if you look at any password system you will find common passwords and if you allow your user to use things like football teams, there own username and words like "god" "jesus" etc then you will get a standard statistical spread. The only conclusion you can make is if you get a million needles and chuck them in the air and do it twice that in pile A and pile B you will find some that point north, its the way it goes.
So what does sony and yahoo have in common - passwords picked by humans, used by humans - just like alot of password systems, be they hashed, tripple hashed or plain old text.
I think we're past the paradigm of gobbledy-gook passwords now. As we learned from xkcd [1], it's possible -- in fact, easier -- to construct a secure password that's also readable as needed.
Wait, what? I'm no security expert, but how does that happen?
Of course it's difficult to verify the genuineness of most disclosures like this, unless the victim company decides to fess up.
There's no evidence that this is indeed from Yahoo Voice, no evidence how old it is, no evidence how Yahoo stored their passwords... And he's only found 300 accounts that existed in both Sony Systems and Yahoo. Quite a leap from some random file someone posted to the web to this.
Is there something wrong with how we tell people their passwords have been compromised - do you think we aren't making it clear enough what they need to do, or how important it is that they do it?
Or perhaps, despite all the reports in both tech and normal media, they just chose not to bother.
I know there are a ton of holes with this but maybe this initial idea could lead somewhere.
People just don't care.
And if 50,000 passwords are cracked, what are the odds that someone is going to use the cracked password to enter your account and do nefarious things, instead of the other 49,999 accounts? Pretty low. And with Yahoo Voice, what's the worst that's going to happen, really?
If it's not the password to your bank account or Facebook, most people are going to figure, it's probably not going to affect me.