LWN.net Logo

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 6, 2012 22:34 UTC (Wed) by endecotp (guest, #36428)
Parent article: 8 million leaked passwords connected to LinkedIn, dating website (ars technica)

I just assume that all passwords I use on the internet are public knowledge. Doesn't everyone? I mean, none of this stuff actually matters, does it? It's not as if it were actually "real life"...


(Log in to post comments)

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 6, 2012 23:49 UTC (Wed) by theophrastus (guest, #80847) [Link]

(..?)
why you're absolutely correct!
what's the password to your bank account again? i seem to have forgot it.

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 7, 2012 1:50 UTC (Thu) by Trelane (subscriber, #56877) [Link]

One.
Two.
Three.
Four...

Five.

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 7, 2012 8:13 UTC (Thu) by dgm (subscriber, #49227) [Link]

That password would make my admin just happy.

Uppercase letters: check
lowercase letters: check
punctuation: check
digits: check, I guess...

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 7, 2012 16:53 UTC (Thu) by endecotp (guest, #36428) [Link]

> what's the password to your bank account again?

My bank doesn't have a password; instead, you need to know a 4-digit PIN, and various easily-discovered facts like the name of my first school.

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 8, 2012 11:24 UTC (Fri) by AndreE (subscriber, #60148) [Link]

So your bank account password isn't important? Or do you use a magical bank that isn't part of "real life"?

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 9, 2012 0:37 UTC (Sat) by martinfick (subscriber, #4455) [Link]

Not if it can be changed by anyone who knows the details he just mentioned. Which is why backup questions are the dumbest things ever. You only have to compromise the weakest link. It doesn't matter how strong your password is if anyone can change it with knowledge of "unchangeable pseudo secrets" about yourself. If I care about security on a site, I would never answer those questions with anything but a random answer (just record it in a safe place).

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds