Tubgirl is Love.
May. 7th, 2007 05:06 pm![[personal profile]](https://www.dreamwidth.org/img/silk/identity/user.png)
An English Wikipedia admin account just got compromised and abused again, because the admin used "fuckyou" as a password. That's the sixth most common password, I think. The main page was deleted for five minutes and Tubgirl was put in the sitenotice.
Brion and Greg are (right now) running a password cracker over the admin accounts. If you want to keep your admin bit and know, deep in your heart, that your password is a bit rubbish, I strongly suggest changing it or it will be locked. Hint: if it shows up in Google, it's a rubbish password. Or enter it into the search box at the right of my Wikipedia blog with your username — I have a, uh, phishing detector running there. Yes, that's it. A note on the subject has been added to Wikipedia:Administrators.
Now we eagerly await Single Crack 0wnz0ring. Normal people just don't get passwords. I used to do dial-up Internet tech support. "What do you want for a password?" "Oh, [username]." "I'm sorry, you can't have it be the same." "Oh, [username]1." Suggestions? Assume we can't require an RSA keyfob for all editors.
(no subject)
Date: 2007-05-07 04:18 pm (UTC)(no subject)
Date: 2007-05-07 04:18 pm (UTC)RSA, and other, crypto tokens suffer from key initialisation problems, but do help somewhat. Until people lose them, etc.
(no subject)
Date: 2007-05-07 04:23 pm (UTC)(no subject)
Date: 2007-05-07 04:29 pm (UTC)(no subject)
Date: 2007-05-07 04:30 pm (UTC)(no subject)
Date: 2007-05-07 04:36 pm (UTC)(no subject)
Date: 2007-05-07 04:37 pm (UTC)(no subject)
Date: 2007-05-07 04:37 pm (UTC)(no subject)
Date: 2007-05-07 04:37 pm (UTC)(no subject)
Date: 2007-05-07 04:37 pm (UTC)(no subject)
Date: 2007-05-07 04:38 pm (UTC)(no subject)
Date: 2007-05-07 04:39 pm (UTC)(no subject)
Date: 2007-05-07 04:39 pm (UTC)(no subject)
Date: 2007-05-07 04:41 pm (UTC)(no subject)
Date: 2007-05-07 04:43 pm (UTC)(I lost my RSA token once. The embarassment was... excruciating. More irritatingly though, I also lost my cute little purple MagLite, my beer bottle opener, and my mini Swiss Army knife, none of which I've managed to replace. Ugh. Totally irrelevant tho.)
(no subject)
Date: 2007-05-07 04:44 pm (UTC)http://hirez.livejournal.com/126331.html (Common p/ws. John the ripper)
http://hirez.livejournal.com/126715.html (Winders non-shite p/w generator)
http://hirez.livejournal.com/127776.html (KDE version)
Though when I say 'non shite' a quick squint at the JtR config shows that the second thing it checks for is the common leet-speak substitutions.
(no subject)
Date: 2007-05-07 04:45 pm (UTC)(no subject)
Date: 2007-05-07 04:50 pm (UTC)harder answer: I forget what it's called because it's not termtime and I've forgotten everything: you know the thing with the client-side image/phrase pair identification?
Really, really paranoid answer: security tokens, biometrics, liens on custody of firstborn, roving bands of angry security people armed with pick-axes and copies of snort. Most amusing, probably not practical.
(no subject)
Date: 2007-05-07 04:50 pm (UTC)(no subject)
Date: 2007-05-07 04:55 pm (UTC)(no subject)
Date: 2007-05-07 04:55 pm (UTC)There is program you can run that won't let you choose a piss poor password. If that's too much for the userbase have john the ripper (or whatever) as part of requests for adminship.
(no subject)
Date: 2007-05-07 04:56 pm (UTC)(no subject)
Date: 2007-05-07 04:58 pm (UTC)(no subject)
Date: 2007-05-07 05:01 pm (UTC)(no subject)
Date: 2007-05-07 05:03 pm (UTC)