Notice of security breach on Ubuntu Forums site
blog.canonical.com
blog.canonical.com
"User" sounds nerdy and impersonal. Consider addressing the affected person directly, using "you" or "your." It is at the same time friendlier and more attention-getting. I would have written:
We take information security and your privacy very seriously, and apologise for the breach and ensuing inconvenience.
At this time,
We have confirmed the attackers were able to access your email addresses and hashed passwords on the Forums site. While the passwords were not stored in plain text, good practice dictates that you should assume the passwords have been accessed and change them. If you used the same password on other services you should immediately change that password.
...etc.
$hash=MD5(MD5($password)+$salt)
These guys think it is incredibly fun to crack Vbulletin passwords as well:
What's stopping it? Are we developers too proud to admit that there is something that we can't do 100% perfectly and it is best left to someone else?
As for your gmail account comment: since most people point their emails to gmail anyway, everything is tied to their gmail account anyway. (e.g. password resets)
If it's separate then at least I can rebind that account to another email address if I choose, such as one I host myself for example. Otherwise if my google account gets closed for whatever reason then I lose all of these other accounts.
You can of course use a different provider but you're looking at either using some other internet giant or hosting your own openID crap which I'd rather have to do.
http://wiki.openid.net/w/page/12995226/Run%20your%20own%20id...
• an incredible amount of power over a lot of people • a HUGE digital bullseye for attackers to aim at
No system connected to the Internet is 100% hack proof.
So what happens when an openid provider with 20 million accounts gets hacked? The attackers now have the potential to access any of the sites you've used openid on.
How about we just try to teach people to be more secure - use strong one way hashes with random salts, dont assume things are secure by default (rails session data in a cookie anyone?), don't trust any user supplied content, etc
One of the most common attacks is compromising a small website or forum, cracking hashes (hopefully it wasn't plaintext), then leveraging those credentials on other sites.
Fewer points of failures through centralized authentication has a lot of benefits:
* People who know what they are doing are handling the security, instead of making site owners (frequently with proprietary code) navigate a minefield they often understand very little about.
* Most users are already forced to have very few points of failures either because of services like LastPass or because they either can't or won't memorize dozens of passwords.
* A centralized, specialized, service would hopefully at least be cognizant of being hacked. Making that assumption with every website you would like to register on does not work.
* Additional security like GeoIP checks and 2-factor authentication can be implemented in a way that applies to many types of sites that simply can't be bothered to do so currently.
The biggest tech companies in the world have all been hacked - what part of "No system connected to the Internet is 100% hack proof." do you not understand?
Right now, it's largely up to users to ensure some sort of post- "password compromised" security, e.g. by using service-sepecific email addresses, service specific passwords, etc. There are third party tools like 1Password that can help with this, and e.g. Apple is integrating similar functionality into Safari for OS X and iOS.
Under your plan, the user doesn't have that ability - they have to find an OpenID provider they're happy to use, and hope it has decent security.
OpenID has many benefits, and its nice to have it as an option for login, but thinking that a mass adoption of OpenID will solve problems of password security and storage, is naïve.
In the quoted sentence I was pointing out that it's not unusual for websites to be completely unaware that they were hacked. It would certainly be unfounded to assume a service couldn't be compromised.
I think it's unreasonable to ask consumers to maintain a large variety of unique passwords. It's a noble goal but it just doesn't happen. LastPass/1Password do solve the password duplication issue, but at the cost of centralizing your passwords and having sites still manage authentication.
Why trust every site you sign up for to properly handle nuances like password character limits and account reset protocols, what if sites let a third party with a narrow focus handle these details?
Password managers are an easier solution to implement, but I don't think they are better than a well designed solution that's similar to Mozilla Persona. If you think otherwise, I'd be happy to hear why.
There are dozens of OpenID providers. The majority, and certainly all the major ones, offer it as part of another service, i.e. Google, Yahoo!, etc.
So to authenticate with some-guys-website.com you want me to then register an account with a third party, because that's better than having a different password for this site?
The likes of Google, Yahoo, etc already have way too much information about what people do, you seriously want to force people to give them more?
I freely admit that there is a problem with the current system, but the solution is not dumping the concept completely and just trusting the likes of Google for authentication everywhere.
It's perfectly possible to have very strong password hashes (e.g. bcrypt/blowfish, scrypt, PBKDF2) but when you have idiot developers, you get bad results.
But email spamfiltering is likely more advanced than similar routines for web fora.
Does anyone remember if that was an option? Or was it only "username/email, password" to log onto the site?
I've just gone through everything and changed to unique passwords stored in KeyPassX.