'Some Idiot On The Internet' Story of the Day

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
Heartbleed bug or not, I don't think posting your passwords on the internet has ever been a good idea. :D

Unfortunately, one of The Switch's readers learned that the hard way. On a story explaining how the Heartbleed bug could slow down the Internet, a commenter scoffed at the "Heartbleed thingamajig," arguing that the Internet's handwringing over security was mostly overwrought. The reader went on to post the two passwords he uses on a regular basis across all of his main accounts.
 
Worst is that he doesn't know that it's not a virus/worm "bug" but a software/program "bug".

I couldn't give a flying fig about the Heartbleed thingamajig. Two years already the thing has been running loose ... and not a word of someone crying over its damage. Say ... does anyone really know its origin? Russian crackers? Seattle high-schoolers? the NSA? Yahoo's marketing department?

idjiots
 
I worked with a guy who made himself a custom "note sync" system that kept his notes in sync between his phone, home computer, work computer, etc.

Unfortunately, the sync mechanism used his personal website as the storage medium.

And the raw text file, while not linked from anywhere, WAS spidered by search engines.

Turns out he spends at least $200 a week on "erotic massages", making sure to "tip <one name> at least $50, but <other name> gets only $30."

Yes, he had plenty of passwords there, including his online banking. And the one that set off ridiculous red flags: he had our product's default admin user name and password in there, along with login information for how to get in to some customer systems! (AKA: he was mixing work and personal notes, including technical support case notes.)

Amazingly, he wasn't fired over it. We REQUIRED him to immediately take the page down, and filed emergency requests with Google/etc, to have the page caches removed.
 
"His accounts were hacked in short order"....jeebus. In what universe does using the passwords someone else moronically provides publicly on the internet qualify as "hacking"
 
"His accounts were hacked in short order"....jeebus. In what universe does using the passwords someone else moronically provides publicly on the internet qualify as "hacking"

Hahaha that was exactly my argument when i got in trouble in grade school for guessing this one guy's password. I mean, it's not hacking if it's the first one i try lol

'nicoleishot' ... i mean seriously?
 
Hahaha that was exactly my argument when i got in trouble in grade school for guessing this one guy's password. I mean, it's not hacking if it's the first one i try lol

'nicoleishot' ... i mean seriously?

But was Nicole actually hot? If so pics are now necessary.
 
Hahaha that was exactly my argument when i got in trouble in grade school for guessing this one guy's password. I mean, it's not hacking if it's the first one i try lol

I got in trouble because I used the password that was written down in the pull out drawer. Don't blame me for their poor security.
 
"His accounts were hacked in short order"....jeebus. In what universe does using the passwords someone else moronically provides publicly on the internet qualify as "hacking"

Social Engineering or Social Hacking, I guess.
 
Hahaha that was exactly my argument when i got in trouble in grade school for guessing this one guy's password. I mean, it's not hacking if it's the first one i try lol

'nicoleishot' ... i mean seriously?

Chocko, as your best friend on Steam, I immediately am requesting the sending of said pics.

Regards,

Send the pics.
 
TBH
If you high secure place is putting the security in you making a secure password. The place at hand DOES NOT understand high security. Im still amazed how far behind on online security USA is in regards to their bank and IRS. It was one of the first hing i noticed moving to the states

The fact is t hat no high secure site should have your entire login security passed on a multi use password. it should be based in single use password like in WoW FFXI and the Danish bank/goverment logins. THE user chocied password should only be a strengthening of th login security NOT its base

i saw banks being interview talking about how uses need to make their password long and secure. totally failing to inform that heartbleedbug retrieved you password so that password security itself was not the problem at hand. but its a nice way for the bank to shift blame away form the fact they use in propper and bad security.


Another way to tell if a site has impropper basic security (not high security), is to try to get your password retried/reset. if the site can actually retrieve your password and give it back to you, its stored in a none safe way (none hashed). password should NOT be stored encrypted (adobe learned that) but hashed with a salt.

User should try to get to use password prehasher to help isolate damage from password retrieved by hacking like heartbleed bug.

https://www.pwdhash.com/


But please do NOT buy into the user faults of long secure password thing. DEMAND your bank and IRS to integrate proper single use password.
 
Would've been epic if his posted financial passwords. :)

You are aware that if you have somebody's email account you can normally reset any account that you want for a person and get access to their bank account or anything else.
 
Didn't you know that if you type in your password it shows as *s for everyone else except you? Even if your told us your password was hunter2 it only shows ******* for us.
 
Didn't you know that if you type in your password it shows as *s for everyone else except you? Even if your told us your password was hunter2 it only shows ******* for us.

Hmm... it seems my [H] password "ihearthardforumlongtimeandtheadminslikechocolate" is not showing up as *s.

Maybe I need to switch to IE8 or earlier for it to work, and uninstall Avast and my router's firewall. :p
 
Hmm... it seems my [H] password "ihearthardforumlongtimeandtheadminslikechocolate" is not showing up as *s.

Maybe I need to switch to IE8 or earlier for it to work, and uninstall Avast and my router's firewall. :p

I can fix that for you, I just need to you run a program to give me full control of your computer for a few minutes.
 
Sure, upload the file to my ftp server:
Code:
ftp://192.168.1.1:21

Anonymous log in and no password.

Actually FTP access won't work. I need you to run go to assist on your computer and make sure to turn off your monitor after giving me access. the process to fix this issue might cause a lot of flashing on the screen as I have to flash the father port on the motherboard. I have special googles so the flash process won't hurt my eyes but since you don't have this it could cause blindness so it is just best that you give me access and turn off your computer to prevent any damage.

So just go to https://gta.notabadsiteatallforyoutobeon.com and enter in the code 1@mn0t@5uck3r and I will be glad to assist you in these password issues that you are having.

:)
 
Didn't you know that if you type in your password it shows as *s for everyone else except you? Even if your told us your password was hunter2 it only shows ******* for us.

Thats not true for passwords since they can be any length and combination of characters, but it is true for social security numbers, since they're all the same. See: ***-**-****
 
What does it say if not that?

Ou.gif
This guy...
 
Back
Top