Ubuntu forums breached - all passwords compromised
ubuntuforums.org
ubuntuforums.org
I do have an ubuntuforums.org account and I DID use a random password so I WAS glad that I didn't have to rush to change all my passwords.
A bruteforcer might find a hash collision, but it's not likely to find the entire string {password}ubuntuforums.org unless it is actively looking for that string.
Granted ofcourse that all websites you do this on store their passwords securely.. if not then you are right, it is a terrible idea :P
$stored = md5(md5($password) + $salt);
That is the simple hash function.
There are sites you can just go to and they'll crack the passwords for you in no time at all.
Edit: aware of rainbow tables and salts and how hashes work etc etc. They are easy to crack if on password lists which they mostly are these days if you have a shit password which is 90%+ of us. Not only that, the $salt on a good chunk of vbulletin sites from vb2 days is not a strong salt.
Go here to get people to crack passwords for you: http://forum.md5decrypter.co.uk/default.aspx
With respect to the feasibility, it's really easy to do an md5 and you don't just do the whole list, you pick interesting email addresses and start there.
What are these sites which will crack the passwords in no time? Try reversing this:
38b2cf16f7be6a1b33097084bed6a4b0:lsdjfldsjlfds
Assuming the password is eight lower case letters, you can try them all in (26^8)/(6.9 billion) = 30 seconds.
Even if the password is eight alphanumeric digits, you can try them all in ((26+26+10)^8)/(6.9 billion) = 8.7 hours.
Now admittedly, many users will have more than 8 characters in their passwords, and 8 hours to crack a single account isn't that bad I mean it could be a lot worse, and it's only a forum so no exactly critical infrastructure. However, by the standards of security systems (where we're used to hearing that brute force attacks will take longer than the age of the universe) MD5 is pretty weak.
In [17]: '38b2cf16f7be6a1b33097084bed6a4b0' == hashlib.md5('lsdjfldsjlfds' + 'asdfasdf').hexdigest()
Out[17]: FalseHashcat is _fast_. It's unlikely the NSA is many of orders of magnitude faster though. I'm happy enough with my 25 random char passwords generated and stored in 1Password.
A journalist[1] got 45% of a list of 17,000 MD5 hashed passwords on his MacBook Air (just CPU hashing no GPU) - in 90 seconds. It's entirely justifiable to expect vbulletin hashes to fall no slower than twice that time.
Even using random passwords - which means "non-dictionary words (including guessable letter/symbol substitution and leading/trailing digits)" - you still need to be aware of the abilities of modern password cracking tools.
Hashcat with a modern gaming video card can do almost 7billion MD5 hashes per second, which'll search the entire 7char password space in something like 90- seconds - or the entire 9char password space in under 9 days. 11 characters gets you up to a _probably_ acceptable 194 years - against a single GPU attacker, the hashcat code will run on 128GPUs at once, which drops that to only ~18months against a well funded attacker (probably "criminal enterprise" level well funded, well short of "nation state" level).
With the Apple password breach - you'd be foolish to not assume criminals could muster hundreds of GPUs to crack passwords that'd give them working iTunes accounts (you give me a couple of tens of thousands of active credit card linked iTunes accounts, and I could think of many ways to turn that into many hundreds of thousands of dollars of revenue for some unscrupulous app developer.) I'm hoping Apples passwords were more securely hashed than salted MD5, but if you were using a less than 10 char password, I'd be changing it immedialtely. Even less that 12 chars might not be safe in a 12 month timeframe...
But you aren't going to remember 11char random passwords anyway, so use a tool (1Password/Lastpass/Keypass/etc) and then there's no point _not_ using 16 or 20 or 25char or longer passwords.
Anything less than 9 random chars pretty much _can_ be cracked "in no time" - any valuable passwords less than 12 chars should be considered "weak".
1. http://arstechnica.com/security/2013/03/how-i-became-a-passw...
[1] http://www.zdnet.com/25-gpus-devour-password-hashes-at-up-to...
function rHash( $rounds, $data, $salt ) {
$data = $data . $salt;
while( $rounds > 0 ) {
$data = hash( 'tiger160,4', $data );
$rounds--;
}
}
And call $stored = rHash( ( registered month + year ), $password );Or even the trusty old...
$stored = crypt( $password, '$2y$14$' . $salt . '$' );
If you're on PHP > 5.4 ( some hosts are still on older versions ), you should check out password_hash() : http://php.net/manual/en/function.password-hash.phpEdit: Fixed some typos.
Many people reuse the same email and password on other services/websites, so this is pretty valuable and sensitive information.
http://www.vbulletin.com/forum/forum/vbulletin-4/vbulletin-4...
any unimportant site that demands a high security password (or low-entropy with silly rules) get put into my keypass.
It allows for much easier filtering of my email as well: I only get the emails I care for in my inbox.