@dianea I tried to send dollars to a school system project and card fee is huge, bank connection doesn't work. Methinks tht's why they have 11 whole supporters.
@dianea I worked on a project where they toyed with keying user accounts on username-password, so multiple users could have the same username but remain distinct because their passwords would be different.
Lead dev was really excited about the idea until I suggested "error: that username-password combination is already in use"
@silvermoon82 @dianea Not quite as bad, but I once inherited a project where the password was a unsalted MD5 hash in the DB, and the login check was literally "... WHERE username = :1 AND password = :2 ...". The key was on a auto-incremented id field. I'm not sure if there was a unique constraint on the username or not.
Admittedly, that was about 20 years ago, when salted hashes were still somewhat fancy, but still...
@silvermoon82 @aserraric I remember my first job maintaining a large manufacturing plant. The network password was three digits: two lower case letters and a number 2. The plant manager did not have a password on their account and one of the guys I worked with read their emails every freaking night.
Now that I think about it, security has not improved. We have Allen Bradley SCADA with detailed access to every relay, substation contactor, chemical pump, and alarm open to the internet.
@aserraric @silvermoon82 @dianea 20 years ago was 2006. I'm pretty sure even Microsoft understood salted passwords before 2006.
The first time I ran into them was my first log in to a Unix machine in 1992. Before then, I had used DOS, CP/M and my trusty C64, and neither of those used passwords, so no point in salting.
What I meant was passwords getting leaked and such. So you would only need one of the two passwords, not both, and you can log in. Hopefully I misunderstood something here… because that's not good…
@plutarch @silvermoon82 True, password reuse is a problem. I swear, after using h*****2 for every one of my accounts for thirty years, so many breaches ☠️
Zak
in reply to Cat 🐈🥗 (D.Burch) • • •masukomi
in reply to Cat 🐈🥗 (D.Burch) • • •Wait. You know what your passwords are?!
🤔 The only passwords I know are the pin codes for my glass slabs, and the master password for my password manager.
Melissa BearTrix
in reply to masukomi • • •@masukomi
I have no idea what my password manager password is ... At all ... Giggles
Hugz & xXx
Æ Sea F.
in reply to masukomi • • •@masukomi
How do you unencrypt your boot partition?
@catsalad
Jack's Poorly Luffed Mizzentop
in reply to Cat 🐈🥗 (D.Burch) • • •Evie 🏳️⚧️
in reply to Cat 🐈🥗 (D.Burch) • • •'Pa
in reply to Evie 🏳️⚧️ • • •George B
in reply to Cat 🐈🥗 (D.Burch) • • •Ryan
in reply to George B • • •calx u-lator
in reply to Cat 🐈🥗 (D.Burch) • • •Jonathan Reiter (张飞)
in reply to Cat 🐈🥗 (D.Burch) • • •ShnoofleBear /ʃnuːfɛlbɛːr/
in reply to Cat 🐈🥗 (D.Burch) • • •Autumn Meadow
in reply to Cat 🐈🥗 (D.Burch) • • •Cat 🐈🥗 (D.Burch)
in reply to Autumn Meadow • • •zeeb-L-thorp
in reply to Cat 🐈🥗 (D.Burch) • • •Cat 🐈🥗 (D.Burch)
in reply to zeeb-L-thorp • • •zeeb-L-thorp
in reply to Cat 🐈🥗 (D.Burch) • • •Cat 🐈🥗 (D.Burch)
in reply to zeeb-L-thorp • • •rj
in reply to Cat 🐈🥗 (D.Burch) • • •Heathen 🐈
in reply to Cat 🐈🥗 (D.Burch) • • •ɐssǝſ
in reply to Cat 🐈🥗 (D.Burch) • • •⏩︎VOTE⏪︎ ᶜʸⁿⁱᶜⁱˢᵐ⁼ᵃᶜᶜᵉᵖᵗᵃⁿᶜᵉ (Ben Royce)
in reply to Cat 🐈🥗 (D.Burch) • • •i'm good
mine is
hunter3
Stuart Longland (VK4MSL)
in reply to ⏩︎VOTE⏪︎ ᶜʸⁿⁱᶜⁱˢᵐ⁼ᵃᶜᶜᵉᵖᵗᵃⁿᶜᵉ (Ben Royce) • • •@benroyce So long as it isn't `dolphins`…
github.com/danielmiessler/SecL…
Remove my password from lists so hackers won't be able to hack me by assafnativ · Pull Request #155 · danielmiessler/SecLists
GitHub⏩︎VOTE⏪︎ ᶜʸⁿⁱᶜⁱˢᵐ⁼ᵃᶜᶜᵉᵖᵗᵃⁿᶜᵉ (Ben Royce)
in reply to Stuart Longland (VK4MSL) • • •@stuartl
😂
Thank you. Hilarious read
M⑨ddie
in reply to Cat 🐈🥗 (D.Burch) • • •Dani
in reply to Cat 🐈🥗 (D.Burch) • • •SackOfBones (any/all)
in reply to Cat 🐈🥗 (D.Burch) • • •Ben Rush
in reply to Cat 🐈🥗 (D.Burch) • • •But what if I added the two digit year at the end? I'm safe then, right?
…right?
for a day, while . . . 🗽
in reply to Cat 🐈🥗 (D.Burch) • • •steve mookie kong
in reply to Cat 🐈🥗 (D.Burch) • • •I got to the password first: h*****1
cc: @amd
diana 🏳️⚧️🦋🌱
in reply to Cat 🐈🥗 (D.Burch) • • •Enter new password: h*****2
Error, password already taken by @catsalad
reshared this
Cat 🐈🥗 (D.Burch) and Lord Caramac the Clueless, KSC reshared this.
cognitively accessible math
in reply to diana 🏳️⚧️🦋🌱 • • •Mx. Eddie R
in reply to diana 🏳️⚧️🦋🌱 • • •@dianea
I worked on a project where they toyed with keying user accounts on username-password, so multiple users could have the same username but remain distinct because their passwords would be different.
Lead dev was really excited about the idea until I suggested "error: that username-password combination is already in use"
reshared this
Cat 🐈🥗 (D.Burch) and diana 🏳️⚧️🦋🌱 reshared this.
diana 🏳️⚧️🦋🌱
in reply to Mx. Eddie R • • •@silvermoon82
I am amazed with Mastodon technology. We no longer have to worry about leaked passwords.
If I type my password and post, it shows up as *******
Lord Caramac the Clueless, KSC reshared this.
social elephant in the room
in reply to diana 🏳️⚧️🦋🌱 • • •Lord Caramac the Clueless, KSC reshared this.
Jens N
in reply to Mx. Eddie R • • •@silvermoon82 @dianea
Not quite as bad, but I once inherited a project where the password was a unsalted MD5 hash in the DB, and the login check was literally "... WHERE username = :1 AND password = :2 ...". The key was on a auto-incremented id field. I'm not sure if there was a unique constraint on the username or not.
Admittedly, that was about 20 years ago, when salted hashes were still somewhat fancy, but still...
Lord Caramac the Clueless, KSC reshared this.
Mx. Eddie R
in reply to Jens N • • •@aserraric @dianea
My very worst was the day I mistyped my email address at Tandy Leather and it still logged me in.
It was apparently selecting on the password, then using the email address to disambiguate, maybe? Anyway, username didn't matter.
They sent me a $50 gift card and a handwritten thank you note after I reported it.
diana 🏳️⚧️🦋🌱
in reply to Mx. Eddie R • • •@silvermoon82 @aserraric
I remember my first job maintaining a large manufacturing plant. The network password was three digits: two lower case letters and a number 2. The plant manager did not have a password on their account and one of the guys I worked with read their emails every freaking night.
Now that I think about it, security has not improved. We have Allen Bradley SCADA with detailed access to every relay, substation contactor, chemical pump, and alarm open to the internet.
Lord Caramac the Clueless, KSC reshared this.
Hisses with Geese 🌱
in reply to diana 🏳️⚧️🦋🌱 • • •Leeloo
in reply to Jens N • • •@aserraric @silvermoon82 @dianea
20 years ago was 2006. I'm pretty sure even Microsoft understood salted passwords before 2006.
The first time I ran into them was my first log in to a Unix machine in 1992. Before then, I had used DOS, CP/M and my trusty C64, and neither of those used passwords, so no point in salting.
Jonathan Lamothe
in reply to Mx. Eddie R • • •Mx. Eddie R
in reply to Jonathan Lamothe • • •@me @dianea
Rich white tech dude, used to being treated as the smartest person in the room and having all his ideas praised by all present.
Bit limited in his vision.
Plutarch
in reply to Mx. Eddie R • • •diana 🏳️⚧️🦋🌱
in reply to Plutarch • • •16 digit passwords are a lot of entropy💪
Plutarch
in reply to diana 🏳️⚧️🦋🌱 • • •Didn't know that, lol (that's interesting, though).
What I meant was passwords getting leaked and such. So you would only need one of the two passwords, not both, and you can log in. Hopefully I misunderstood something here… because that's not good…
diana 🏳️⚧️🦋🌱
in reply to Plutarch • • •True, password reuse is a problem. I swear, after using h*****2 for every one of my accounts for thirty years, so many breaches ☠️
TeflonTrout he/him
in reply to diana 🏳️⚧️🦋🌱 • • •I switched mine to correcthorsebatterystaple and haven't had any problems
Defaulty 🇨🇦
in reply to Cat 🐈🥗 (D.Burch) • • •uvok Grumpyspots
in reply to Cat 🐈🥗 (D.Burch) • • •Cat 🐈🥗 (D.Burch)
in reply to uvok Grumpyspots • • •Linda Sgoluppi Artist
in reply to Cat 🐈🥗 (D.Burch) • • •Ben S.
in reply to Cat 🐈🥗 (D.Burch) • • •Cat 🐈🥗 (D.Burch)
in reply to Ben S. • • •Robin Forlonge Patterson
in reply to Cat 🐈🥗 (D.Burch) • • •Dev swami
in reply to Cat 🐈🥗 (D.Burch) • • •Dev swami
in reply to Cat 🐈🥗 (D.Burch) • • •KNova
in reply to Cat 🐈🥗 (D.Burch) • • •@LoganFive not gonna dig it up, but I love that meme that I think you’ve posted at least once…
“Error: the password you’ve chosen is already in use by Carol in accounting”
TagHunt
in reply to Cat 🐈🥗 (D.Burch) • • •Ren
in reply to Cat 🐈🥗 (D.Burch) • • •eviloatmeal
in reply to Cat 🐈🥗 (D.Burch) • • •spaduf
in reply to Cat 🐈🥗 (D.Burch) • • •groxx
in reply to Cat 🐈🥗 (D.Burch) • • •john lomax
in reply to groxx • •No, luggage knows its owner and will get back to them regardless of who or what is in the way!!
#Pratchett
groxx likes this.