Xkcd: Encryptic
xkcd.com
xkcd.com
>>It was bound to happen eventually. This data theft will enable almost limitless [xkcd.com/792]-style password reuse attacks in the coming weeks. There's only one group that comes out of this looking smart: Everyone who pirated Photoshop.<<
[xkcd.com/792]: http://xkcd.com/792/
- depending on the for-profit company
- having disadvantage on the marketplace because of inferior tools
I think the former is often preferable.
"Since DES only encrypts in blocks of 64 bits (8 bytes) then encrypting and keeping the length of blocks means that you actually get a very good idea of the length of the password - that is, anything with only one block is a password length between 1 and 8 characters, with two blocks between 9 and 16 characters etc. In addition a password of "1234567812345678" would encrypt into two identical blocks."
ECB mode is just terrible. As well as these suffix problems, I've seen another example where a company used it to encrypt key-value pair cookies. Of course the keys are always the same...so prefixes were guessable too. And wikipedia has a fantastic example of why its stupid for images:
http://en.wikipedia.org/wiki/ECB_mode#Electronic_codebook_.2...
I'm not sure if this is the case, but sometimes this has to do with 'backwards compatibility'. I've seen databases where some passwords where MD5, some SHA1, some Bcrypt and so on. The login page then will do something like:
if(checkBcrypt(password)) {
login();
} else if(checkSha1(password) || checkMd5(password)) {
updateDbPassword(password);
login();
} else {
loginError();
}In general, using any mode of encryption (rather than hashing) on passwords is dumb. But this is dumber than usual.
which makes me think...
Why the hell hasn't Adobe reset everyone's password yet? That would be the FIRST thing I did in that situation. At least prevent the world from being able to log into my own site with the leaked passwords.
nospam@nospam.com
nospam@here.com
Were all found.
I feel sorry for the people paying a lot of money to buy these short domain names, and finding huge amounts of spam being delivered to them because people have misused domain names that don't belong to them.
I agree that I'm quibbling over probably unimportant details :-)
But until someone does, you could just Google "most common passwords" and if yours is in the set, you win!
One super-good thing I did when I signed up for adobe was:
I created a separate email address (purely by co-incidence) that I used exclusively for Adobe (and for some spammy services like some deal sites, which didn't require my card). As a result, I know for sure that my card was compromised because of the Adobe's breach and no one else.
Lessons and observations:
1) I'm glad I bought the CS6. With the cloud comes great risks too. Not to say that you should avoid cloud products, but when you have a version you can own forever, then you might as well go for it. Imagine if I was on CC and my card was hacked and I decided to stop paying Adobe the next month out of frustration. Do you know what will happen? My company will come to a stand-still because I will no longer have access to Photoshop and a huge portion of my company is basically a Media company.
2) Someone else said we're depending too much on Adobe, and I tend to agree. But there is really no superior equivalent for Adobe's Photoshop at the moment. Please don't cite GIMP - I've tried it and it needs a lot of work to even be on par with Photoshop atm. Another factor is the PSD file format which has painfully spread like a Virus and you can't erase it out of your workflow if you're a Media shop like us (Most printing services accept PSDs/TIFF). I sincerely wish why YC companies who generally want to change the world, don't want to create a Photoshop clone/competitor to kill this stupid Adobe that's ruining all of our lives with the stupid CC bundle.
3) The people who really won, like someone else said, were the ones who used pirated versions. I mean, I've paid a total of ~$1400 till now to Adobe and what have I received from Adobe? A 'fuck you' from their CEO in the form of their Creative cloud bundle and a hack that leaked my personal details online making me look like a jack ass to anyone who searches for me by my email. Oh also don't forget the uncounted number of "fuck you's" he's sent me while developing for Flash (on mobile) and Flex.
4) Always create a separate email (or an alias) while signing up for cloud services, so you can eliminate guess work during a crisis. So, instead of signing up with example@gmail.com for Adobe or someone else, use example+adobe@gmail.com (this will redirect to example@gmail.com) or rather create adobe.example@gmail.com or something (gmail is just an example). This way, you can always trace out the right service responsible for the leakage of your details whenever something goes wrong.
I was lucky enough that my bank blocked my card on observing a fraudulent transaction initiated from another country and thus issued me with a new card. I have no plans to upgrade from CS6 or to something else for the next few years. Hopefully GIMP will get better by then, or some YC company will create a better Photoshop and let us own it forever for a one-time fee.
>4) Always create a separate email (or an alias) while signing up for cloud services, so you can eliminate guess work during a crisis. So, instead of signing up with example@gmail.com for Adobe or someone else, use example+adobe@gmail.com (this will redirect to example@gmail.com) or rather create adobe.example@gmail.com or something (gmail is just an example). This way, you can always trace out the right service responsible for the leakage of your details whenever something goes wrong.
Doesn't stop someone just removing the + tag on the email address.
A better way is to set up a catch all on a domain... but then you're likely to get a lot more spam... (to things like mail@, contact@ and a whole bunch of firstnamelastname@ guesses)
It won't stop spam but the biggest risk with these leaks is from automated testing of a password found from a leak on one service you use with the same email address on another. As long as you use a separate + address for both you'll be safe as they are unlikely to automate testing of different + addresses since most users don't do that.
> A better way is to set up a catch all on a domain... but then you're likely to get a lot more spam
I forward my catch all domain emails to gmail. I hardly get any spam now except to leaked addresses which I've filtered to add bright red labels so I can ignore them.
If I were attempting to exploit the Adobe list, every email address I saw like name+adobe@example.com, I'd try the exposed password using not just name+adobe@example.com and name@example.com, but also name+othertarget@example.com, where "othertarget" might be something like twitter, facebook, paypal - depending on where I'm attempting to misuse the exposed credential.
Hmm. I was one of the hacked users, but googling my email doesn't come up with anything.
Note the apparent password hints "Our business unit plus 1" or "usual one." Really crosswordy.
St.peter
St.peter
St.peter1
password
password1
password57
seem to be the first few if I understand correctly.
You can tell them apart (sometimes) because "exactly 8 characters" will match if those 8 characters are re-used by someone else with a longer than 8 character password.
And the layout emphasizes the re-use, which is also shown by color coding.
2. If adobe weren't completely stupid (a big if admittedly) it will be infeasible to brute force (>100 bits of entropy)
Really? Even a massively distributed attempt?
Even if you somehow managed to get a botnet of 100 million machines, it would still take longer than the age of the universe to brute force it.
Security of 3DES is effectively 112 bits [2] if random keys are used. Although as I said, this is assuming adobe weren't completely stupid (and reused one or more of the keys, or used non-random keys)
[1] https://dl.dropboxusercontent.com/u/209/zxcvbn/test/index.html
[2] http://en.wikipedia.org/wiki/Triple_DES