LWN.net Logo

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 6, 2012 23:49 UTC (Wed) by theophrastus (guest, #80847)
In reply to: 8 million leaked passwords connected to LinkedIn, dating website (ars technica) by endecotp
Parent article: 8 million leaked passwords connected to LinkedIn, dating website (ars technica)

(..?)
why you're absolutely correct!
what's the password to your bank account again? i seem to have forgot it.


(Log in to post comments)

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 7, 2012 1:50 UTC (Thu) by Trelane (subscriber, #56877) [Link]

One.
Two.
Three.
Four...

Five.

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 7, 2012 8:13 UTC (Thu) by dgm (subscriber, #49227) [Link]

That password would make my admin just happy.

Uppercase letters: check
lowercase letters: check
punctuation: check
digits: check, I guess...

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 7, 2012 16:53 UTC (Thu) by endecotp (guest, #36428) [Link]

> what's the password to your bank account again?

My bank doesn't have a password; instead, you need to know a 4-digit PIN, and various easily-discovered facts like the name of my first school.

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 8, 2012 11:24 UTC (Fri) by AndreE (subscriber, #60148) [Link]

So your bank account password isn't important? Or do you use a magical bank that isn't part of "real life"?

8 million leaked passwords connected to LinkedIn, dating website (ars technica)

Posted Jun 9, 2012 0:37 UTC (Sat) by martinfick (subscriber, #4455) [Link]

Not if it can be changed by anyone who knows the details he just mentioned. Which is why backup questions are the dumbest things ever. You only have to compromise the weakest link. It doesn't matter how strong your password is if anyone can change it with knowledge of "unchangeable pseudo secrets" about yourself. If I care about security on a site, I would never answer those questions with anything but a random answer (just record it in a safe place).

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds