Disqus cracked – Security flaw reveals users’ e-mail addresses
cornucopia-en.cornubot.se
cornucopia-en.cornubot.se
The slippery slope is
Being politically affiliated with hate speech IS a choice.
That is some straight up false equivalency bullshit.
The problem with making speech legal or illegal based on popular opinion of it, is that one IS perfectly capable of engaging in hate speech without choosing to do so. What happens when what I said online two years ago becomes hate speech tomorrow? Do I need to make sure I go scrub all of my past speech before anyone finds out and sends me to jail?
Furthermore, one "chooses" their future course, and whether they want to self-identify with one group more than another. To claim otherwise is to deny any semblance of free will. I know many people who choose to identify with the gay community that aren't gay, and many who choose to NOT identify with the gay community who are gay.
False equivalency rains down wonderfully on the head of a man imprisoned for speaking his mind. You can tell him all day how he chose to be in jail.
I am disagreeing with you on one point. Being Jewish is a choice, just like being Christian is a choice. I was born into a family, like most, with generations of religious belief. I, however, am an atheist. You don't have to be a Jew. You can have jewish culture in your life, respect it and enjoy it. That does not mean you have no choice but to also be religious. That part is a choice. Just as it is for anyone from any other religion.
Do you think that proponents of Neo-Nazism (etc) really care about the distinction between "born into a Jewish family" and "is a member of the Jewish religion?" I'm not saying that there isn't a distinction, but people engaged in hate usually aren't too interested in nuance.
For every example we care to provide there's probably a deviant group more than willing to discriminate against that population and even want to kill them. I think the history of genocides more than proves that point.
Please don't be offended. Jews don't really have a monopoly on being hated or being murdered en-masse. Many argue --quite convincingly-- that the Jewish genocide was modeled after the Armenian genocide of 1914/15 (the Nazi's copied some of the methods the Turks used on their Armenian population).
In the US, at least, in non-deviant circles, I believe you can be a person and not someone "born into an <X> family". In that context whatever you push in front of people as what defines you is up to you. Believe it or not, as an atheist I have a number of good friends who are Born Again Christians. Every single one of them is a great person. Each one of them chooses to define themselves by their religion differently. One in particular will smash you in the face with it every chance he gets. Not surprisingly he has suffered greatly with employment because, well, this isn't something you wear on your forehead and pester people with at work. The other guys are just guys who happen to privately be BAC's. He is a militant BAC. Choice.
The normal US point of view is that "Jewish" is a religion, not an ethnicity, hence is a choice.
That point of view is not universally shared, of course.
A cursory search tells me nothing of much use.
Apropos of nothing, I found a Pew poll[0] that says... 21% of atheists believe in a god? Huh?
[0] - http://religions.pewforum.org/pdf/report2religious-landscape... ("Conception of God")
And again, if you talk to people who self-identify as "Jewish", you get a rather more complex picture.
The crack was done in cooperation with the Bonnier Group tabloid Expressen, in order to reveal politicians commenting on Swedish hate speech-sites.
Exposing politicians is a time honored practice in all countries and across all ideologies. It's possible that the hacking is still a crime in Sweden, regardless of the motives. No one is defending it--you seem to have done that on your own, as the linked article certainly does not.
Your comments to gay rights groups, anti-gay rights groups, cancer support groups, aids support groups, abortion groups, democratic politics, tea party groups, gun rights groups, doctors offices, anyone using wordpress as a front end group.
Anyone can do this with a simple search engine they create, and apparently we don't care because gravatar was setup by a silicon valley favorite and is now owned by Wordpress who was informed of this years ago and refused to consider it a privacy leak. And anyway we like them cutsie cartoon avatars.
Anyone can do this with a search engine that maps pages to md5 hashes and vice versa and either a rainbow table of email addresses, or even easier, a list of your customer's email addresses, because let's see if any of our customers have health problems they didn't disclose.
If you don't want a particular comment associated with your name or email, why would you ever fill in that name or email when commenting?
"Email (required) (Address never made public)"
MD5 leaks of my email address into web pages is in fact making my address public.
Hey lmm, duh, when you make a comment under a different name but with the same email address that you think is anonymous at your local hiv testing site, you may not expect that your insurance company can track that down because wordpress has been leaking your md5 address all over the place.
So wordpress - not disqus or gravatar (which I'm aware is owned by wordpress) - is lying to you. Let's put the blame in the right place.
Saying that your email is kept private by taking its MD5 sum is like expecting than an unsalted MD5 sum for a password hash in a publicly accessible password database will be secure for people with weak, brute-forcible passwords like "1234". You are providing a little bit of obfuscation, but no real security.
I am foo@bar.com. I don't know who owns that email, but I want to preemptively apologize to them about Disqus comment responses they've received.
Theres a security problem with Disqus.
Apparently it (genereal technique) is "old news"
Apparently Disqus doesn't care enough to fix it.
Demonstrating the attack may be the only way to get them to care.
So from the beginning, I think it was always obvious that Disqus had no interest beyond the bare minimum in casually protecting user privacy. This prompted me to avoid ever providing Disqus with any kind of serious e-mail address. Looks like my instincts served me well.
How would you use it otherwise? My backyard is private, but I share it with a few 3rd parties. That doesn't mean i intent to share my backyard with the entire world.
There is an element of trust with particular 3rd parties that is being violated. Why is that so hard to understand?
Unless you run your own mail server, someone knows your email address, so are you trying to define that as not private? Obviously, we are using fuzzy terms about private/public when there is a huge gradient of privacy.
The party has its roots in the skinhead/neo-nazi organizations and they have been trying to shake that image problem for quite some time now. To be fair, putting on suits has helped them.
95% of the population has absolutely no clue about how technology works and how it will be used against them, sooner or later.
Why not public? I guess it's fine if everyone knows it assuming a perfect spam filter (they aren't perfect btw) but I don't want it to be public knowledge what websites I use and what I say on those sites. Non-sinster example; I could be publicly discussing a sexual encounter and just not want the whole world to know (non-psuedonymously) that I did that.
And E-Mail-addresses aren't passwords; trying a few hundred variations for each firstname for each lastname is perfectly feasible and should crack a nice percentage of these hashes.
(of course, my real name can be extrapolated from my HN username)
Your call on whether "An adversary can only defeat my security given three hours and a hardware investment of $1,600 2010 dollars" is an acceptable security bound for your users. If it isn't, don't use MD5 for crypto purposes.
Still, I don't think I've ever had a rainbow table that contained plaintexts longer than 12 characters. Are 30+ length tables common these days?
You’re correct that brute force with an entropy of 3 per bit would still be too big for rainbow table usage (like 10^15 PB too big).
I reported a username -> plaintext email vuln to Disqus earlier this year and they were very prompt in patching it, I wouldn't criticize them for this at all as this a very common issue across most blog comment systems.
Would be nice to change how Gravatar works, but it's fairly fundamental. I think if you want your email to be private you should probably be registering temporary ones or using the + aliases like gmail offers to avoid these kinds of hash-cracking attacks.
http://hashcat.net/oclhashcat/ https://www.tarsnap.com/scrypt.html https://en.wikipedia.org/wiki/Bcrypt
Even a slower or more "secure" hash wouldn't help much, because I can take your starting known email address and find comments you have made. i.e. I can start with "bill@example.com", slowly hash that to 901e54d1 and then search google for 901e54d1 to find comments you've made.
Speed isn't a big deal if I'm interested in attacking specific subsets of emails. (Which could still be a "large" set in a real world sense.)
As long as the hashing algorithm is known then it would be weak to finding comments made by known authors. If the hashing algorithm is unknown then it falls under security by obscurity.
So is there any way to implement a decentralised pseudonymous but ID-based system where the ID is tied to email but cannot be generated from email (or rather is generated from email but with some added entropy that prevents going in either direction in the future.).
I'm guessing Hashing (not MD5 though) + Salting + throwing away the salt and bruteforcing it every time you need the plain email (you will lose the option to mass mail your users)
Even then the whole concept of anonymity AND email bound account seems kind of silly. Even if the user uses a secondary email address just for this, he still has to trust the email provider (and if he uses a throwaway, what is the point of collecting it anyway?)
This crack is proof that services that provide a fake sense of anonymity can do a lot of harm.