FBI got Hacked, Reveals Hundreds of Passwords
pastebin.com
pastebin.com
> Joseph McQueen III, chief of the FBI personnel recruitment unit according to [0].
daniel.clegg@ic.fbi.gov - clegg.passwd
> is an FBI supervisory agent
Some others
laura.eimiller@ic.fbi.gov - passwored12
William.So@ic.fbi.gov - cutelilyian191
tammy.mchugh@ic.fbi.gov - passwords123456
Rich.Ernst@osd.mil - ernst.richard
celkins@vertizontalinc.com - celkins.vertizon
joseph.herold@us.af.mil - 128482joshqwerty
joseph.s.dufresne@uscg.mil - qwerty9876
IC_Complaints@ic.fbi.gov - JulianICcomplaints
gavin.edward@bdsus.mod.uk - eduardopassword123
IC_Complaints@ic.fbi.gov - JulianICcomplaint
ronald.menold@ic.fbi.gov - password111111
[0] http://www.diversitycareers.com/articles/pro/09-augsep/dia_f...
It seems someone else already did this hack and these guys simply copy-pasted the passwords to make it look like their hack. Apparently, these copy-pasters are The Hackers Army from Pakistan.
This link on Hackernews is nothing but a publicity stunt by THA. Waste of few minutes of my life.
passwords123
passwored12
password$qwerty
qwertylol@me
passwords123456
password123
password111111Also, for some more reading on why using spaces will make it infinitely more difficult for hackers to try and gain access: http://www.baekdal.com/insights/password-security-usability
Deleted comment
It appears that, in general, the FBI staff are setting reasonable passwords. There are a few passwordNNN types but the majority are adequate and, in my opinion, would hold up well against a brute force vector, which is the primary purpose of password complexity.
> ctsecuritiesfraud@ic.fbi.gov - fraudadmin
I didn't believe in those quotes and every time a situation like this happens I'm more convinced that they are no more advanced than the big companies (Microsoft, Mozilla...) and depend heavily on the updates released by those companies every week... Just my 5 cents...
How can an organization be seven years ahead of everyone else? Do they have Norton Antivirus 17.0, whereas the rest of us are using 10.0?
As opposed to the Hollywood scenes of ultra high tech rooms with floating transparent screens, shiny lights everywhere, and super advanced systems that can listen to your voice commands and instantly solve complex cases just by saying "enhance!". Which is probably the vision this person who talked to you had. Reality is more like windows xp and programs that compile even when the unit tests fail.
For example I bet this wouldn't pass the FBI's requirements:
- Clowns with clown makeup
But this would:
- password123
Amongs the passwords I see: marklevett, looskwoooish or even qwertylolqwerty.
Browsing the list the only think I could think they enforced was a minimum character count. I see no whitespace or underscores either.
So I guess Clowns.with.clown.makeup would've worked.
Anyway, the real issue is: why were those passwords stored as plaintext?
PS - "reverse" just means using either rainbow tables or generating the entire set for a given hash(n).
The reality is that employees can't be trusted to manage password strength. But it's trivial to implement a validation scheme that forces employees to be over a minimum length, use special characters, etc. Of course this is also not great -- and inevitably we'd see Pa$$word123 -- but it's at least a starting point.
Whoever wrote the code that stored these values in plaintext (if that is indeed the case) should definitely get the boot.
If this was the NSA or CIA I would fire them all and shoot the person who coded it. :o)
Of the rest, some are human inputted for sure but some seem randomly generated.
Can I venture guess that some weak accounts are pretty trivial and the important one's are using randomly generated passwords? Yes it's still bad practice, weak link and all that. I'm not condoning such practice.
So you make a post about it?
Some of my favourites:
$$$$$$$$$$$$$
bebrian.nerd
ilovemydaughternancy
sallymylove1981
lisa.grossmanThe simple passwords are too simple [ali@ic.fbi.gov - noentryplease1897182 - really?] and the complicated ones are way too complicated [I assume they don't use tools like 1Password and such].
Also most of the emails are firstname.lastname@... and every 3rd of 4th is Firstname@... and some of them are really weird, like SCAM@ic.fbi.gov - juyt8&81igasd, Bogdan@ic.fbi.gov - 19127gasdg8991872
Things like "recruits.membership" for the recruits maybe not so much.