Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm sorry, but when was the last time anyone heard of anyone guessing a password? Sure, it's a very easy password to brute force, but it doesn't matter that it's the number of the paper, because nobody would have thought to try it, along with the thousands of other things it could be, each spelt in a variety of ways.

It's much more probable that they brute-forced it in microseconds from the md5 hash, which is where the actual weakness is. I will go so far as to say that, had they used bcrypt, this would have not been broken, because people don't usually go around gathering personal data about you to try by hand (unless you have the CIA interested, that is, and then they can get in in easier ways).



I pulled a machine out of a garbage pile once. Booted it up, it required a password, I guessed "password" and it logged me in as the CEO of the company.

So, in your case, the last time you heard of anyone guessing a password was about a second ago.


A college student I know likes to play a certain online game. Some accounts have items and status symbols that are valuable in-game, but the accounts are abandoned for years. Some names are even intrinsically valuable (names like "Sun" or something like that). This college student, at least once a month, guesses the correct password for these old accounts based on information the users provided years ago.


That is far cooler than what I did: your friend actually engages in an intellectual exercise, I just got lucky with a guess.


Your story is certainly one to remember though (and lucky that it was a business owner!) I have to say though, it's quite fascinating to watch my friend work. She would make a gifted detective...


>information the users provided years ago

Just curious, but what in particular? Their profile page, logs of forum conversations? And how does he/she generate the guesses? It seems like optimally you'd have some kind of tool which constructs permutations of likely words (sun, 5un, sun!, etc).

...Honestly just curious, promise I'm not planning anything evil.


She doesn't use any tech like that, no. Profile page is one source of information. It happens to be a site where people share a lot of interests and things like that, so there are a number of profile pages. She finds out what they named their possessions, on this account and others. She searches the usernames in other places. A lot of times she also finds or guesses an email address which hotmail deleted years ago, makes it, and then the site sends the password to her new account.


A few jobs ago, I needed to make some copies, but a five-digit PIN had just been put on the machine. Before going and asking anybody, I tried the building's zip code, which worked.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: