Tubgirl is Love.
May. 7th, 2007 05:06 pm![[personal profile]](https://www.dreamwidth.org/img/silk/identity/user.png)
An English Wikipedia admin account just got compromised and abused again, because the admin used "fuckyou" as a password. That's the sixth most common password, I think. The main page was deleted for five minutes and Tubgirl was put in the sitenotice.
Brion and Greg are (right now) running a password cracker over the admin accounts. If you want to keep your admin bit and know, deep in your heart, that your password is a bit rubbish, I strongly suggest changing it or it will be locked. Hint: if it shows up in Google, it's a rubbish password. Or enter it into the search box at the right of my Wikipedia blog with your username — I have a, uh, phishing detector running there. Yes, that's it. A note on the subject has been added to Wikipedia:Administrators.
Now we eagerly await Single Crack 0wnz0ring. Normal people just don't get passwords. I used to do dial-up Internet tech support. "What do you want for a password?" "Oh, [username]." "I'm sorry, you can't have it be the same." "Oh, [username]1." Suggestions? Assume we can't require an RSA keyfob for all editors.
(no subject)
Date: 2007-05-07 04:18 pm (UTC)(no subject)
Date: 2007-05-07 04:36 pm (UTC)(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
Date: 2007-05-07 04:18 pm (UTC)RSA, and other, crypto tokens suffer from key initialisation problems, but do help somewhat. Until people lose them, etc.
(no subject)
Date: 2007-05-07 04:37 pm (UTC)(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
Date: 2007-05-07 04:23 pm (UTC)(no subject)
Date: 2007-05-07 04:37 pm (UTC)(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
Date: 2007-05-07 04:37 pm (UTC)(no subject)
Date: 2007-05-07 04:29 pm (UTC)(no subject)
Date: 2007-05-07 04:30 pm (UTC)(no subject)
Date: 2007-05-07 04:37 pm (UTC)(no subject)
Date: 2007-05-07 04:39 pm (UTC)(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
Date: 2007-05-07 04:44 pm (UTC)http://hirez.livejournal.com/126331.html (Common p/ws. John the ripper)
http://hirez.livejournal.com/126715.html (Winders non-shite p/w generator)
http://hirez.livejournal.com/127776.html (KDE version)
Though when I say 'non shite' a quick squint at the JtR config shows that the second thing it checks for is the common leet-speak substitutions.
(no subject)
Date: 2007-05-07 04:55 pm (UTC)(no subject)
Date: 2007-05-07 04:58 pm (UTC)(no subject)
Date: 2007-05-07 05:01 pm (UTC)(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
Date: 2007-05-07 07:08 pm (UTC)So I reuse passwords. It's not great security, but for crap like Wikipedia that I don't use very often it's a lot easier to know that it's one of three passwords rather than a unique password that I won't remember.
(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
From:(no subject)
Date: 2007-05-07 05:12 pm (UTC)cracklib for the password creation/changing bit, and weekly (at the very least) 2h-runs of john against the password-file. This combination works wonders against most common bullshit users come up with.
(no subject)
Date: 2007-05-07 05:15 pm (UTC)(no subject)
From:(no subject)
Date: 2007-05-07 05:19 pm (UTC)(no subject)
Date: 2007-05-07 05:55 pm (UTC)Vasco make tokens without many of these disadvantages, as do others; finding a suitably open-content/source/culture friendly vendor and hitting them up for a donation of 2000 tokens is left as an exercise.
(no subject)
Date: 2007-05-07 07:58 pm (UTC)(no subject)
Date: 2007-05-07 08:53 pm (UTC)https://secure.wikimedia.org/wikipedia/en/wiki/User:AndyZ
https://secure.wikimedia.org/wikipedia/en/wiki/User:Jiang
https://secure.wikimedia.org/wikipedia/en/wiki/User:Conscious
https://secure.wikimedia.org/wikipedia/en/wiki/User:Marine_69-71
Lets hope we find them all first.. ffs..
(no subject)
Date: 2007-05-07 10:06 pm (UTC)(no subject)
Date: 2007-05-07 10:55 pm (UTC)Well fuck there's a website. Who would have thought.
(no subject)
Date: 2007-05-08 03:25 pm (UTC)(no subject)
Date: 2007-05-07 11:56 pm (UTC)- 6-digit PINs
- Not containing the extension backwards or forwards
- Not being in similar form to 111222, 123321, 123123, 112233
- And block the login ability after two failed attempts
.That was hard enough to get people to understand. Eventually, "if you don't let me do this, it'll cost you MONEY, as inm hundreds of quid a day, if you're unlucky" brought the point home.
(no subject)
Date: 2007-05-08 02:17 am (UTC)I assume it's a reasonably secure method for generating them, since he cared about such things, and I always found it reasonable to remember. (One of my passwords for a while was, for example, HiwYwH42.)