10 ms·
I Am Releasing Ten Million Passwords
- pbhjpbhj 12y agoSo this guy found a zero-day that works across different unzip binaries, or what ...!?
- deleted 12y ago[deleted]
- tptacek 12y agoBarrett Brown was not convicted merely for linking to data on the web. He was convicted for three separate offenses: 1. Acting as a go-between for (presumably Jeremy Hammond) the Stratfor hacker and Stratfor itself, Brown misled Stratfor in order to throw the scent off Hammond. Having intimate knowledge of a crime doesn't make one automatically liable for that crime, but does put them in a precarious legal position if they do anything to assist the perpetrators. 2. During the execution of a search warrant, Brown helped hide a laptop. Early in the trial, in advancing the legal theory that hiding evidence is permissible so long as that evidence remains theoretically findable in the scope of the search warrant, Brown admitted to doing exactly that, and that's a crime for the same reason that it's a crime when big companies delete email after being subpoenaed. 3. Brown threatened a named FBI agent and that agent's children on Twitter and in Youtube videos. The offense tied to Brown's "linking" was dismissed. Brown's sentence was unjust, but it wasn't unjust because he was wrongly convicted by a trigger-happy DOJ; rather, he got an outlandish sentence because he managed to stipulate a huge dollar figure for the economic damage caused by the Stratfor hack, which he became a party to when he helped Hammond.
- sarciszewski 12y ago> Barrett Brown was not convicted merely for linking to data on the web. From the article: Most of us expected that those charges would be dropped and some were, although they still influenced his sentence. I want to be generous and say that the author meant what you said. The linking was not something Brown was charged with, but it was brought up during the sentencing and probably influenced the length of his prison sentence. So while you're correct that Brown was not charged with linking to information, it's worth noting that this was still used against him anyway. Also, people who think the linking to hacked data was the only thing that got him arrested are being disingenuous (or are simply ignorant).
- tptacek 12y agoI'm not seeing where the linking was used to enhance his accessory conviction. Is there a source for that?
- m8urn 12y agoThe trafficking charges were dropped but he still was charged as an accessory after the fact. http://cryptome.org/2015/01/brown-105.pdf http://cryptome.org/2015/01/brown-105.pdf
- tptacek 12y agoYes; that's #1 in my list. Thanks for the link to the sentencing memo!
- dmix 12y agoI never followed the case, could someone clarify how he was an accessory after the fact? Did they explain how he misled Stratfor? Were they investigating their own breach and contacted him somehow? Or did he hide evidence? It'd be great to have clarity on his wrongdoing related to the hacking. The parts about threats and hiding evidence seem tertiary to peoples defense of him. Since the major crime that he became famous for was the hacking by anonymous.
- tptacek 12y agoAccording to Kim Zetter: The first charge is a new one and relates to assistance Brown allegedly gave the person who hacked Stratfor “in order to hinder and prevent [his] apprehension, trial and punishment.” According to the government Brown worked to create confusion about the hacker’s identity “in a manner that diverted attention away from the hacker,” which included communicating with Stratfor after the hack in a way that authorities say drew attention away from the hacker. The hacker is not named, and it’s not clear if it’s convicted Stratfor intruder Jeremy Hammond, or an earlier hacker who’s known to have penetrated the company first.
- dmix 12y agoThanks. Seems like during sentencing this was the key point related to accessory: > Loss amount of more then $400,000 but less than $1M This was worth +14 points which was higher than any other single guideline - including threatening an FBI agent. I guess the lesson here is that if the crime at hand involved any significant amount of money then even if your role was minor (and after the fact) you can still get serious punishment.
- egocodedinsol 12y agobut what do you think about the big picture? I don't know much of the specifics about Brown, but I think the wider point is worth discussing, especially with respect to the proposed change in legislation.
- Slartibreakfast 12y agoI don't know, sounds like he got off pretty lightly considering he threatened an FBI agent's children. I would expect the jail time would be a lot higher, but I guess I don't know what guides the court's decisions in these kinds of cases. I suppose five is enough time for him to figure out the error of his ways.
- tptacek 12y agoHis sentence was dominated by the accessory charge, and the threats don't seem to have been a factor at all.
- dsrguru 12y agoThe threats actually accounted for 48 of the 63 months according to the EFF article that the OP linked to. https://www.eff.org/deeplinks/2015/01/eff-statement-barrett-brown-sentencing https://www.eff.org/deeplinks/2015/01/eff-statement-barrett-...
- tptacek 12y agoEFF's reporting appears to be contradicted by the (now public) sentencing memo. Orin Kerr analyzed it at length for WaPo a few days ago.
- dsrguru 12y agoStrange. Almost every article I'm finding echoes the EFF's statement about 48 months, but Judge Lindsay's own explanation of the sentencing is as Orin Kerr says. I wonder where that 48 figure came from. http://www.washingtonpost.com/news/volokh-conspiracy/wp-content/uploads/sites/14/2015/01/show_temp.pl_.pdf http://www.washingtonpost.com/news/volokh-conspiracy/wp-cont...
- throwawaykf05 12y agoI think you've simply stumbled upon another illustration of how modern "journalism" works :-) What was that quote about a lie traveling halfway around the world before truth has its pants on? This is not the first time the EFF has done this, by the way.
- jbapple 12y agoWhat were the threats against the agent and the agent's children? I'm asking because I read some of them ("ruin his life", "look into" his kids), but I'm not sure which of those are protected under the First Amendment. Broad categories of rude speech are protected under the First Amendment, including things like, IIRC: 1. Saying if President Johnson makes you pick up a gun, he'll be the first in your rifle sight. (Watts v. United States) 2. Telling a cop "I'll kill you, you white devil" while you are in handcuffs and unable to kill him. (? v. ?) 3. Swearing "revengeance" upon the Jews. (Brandenburg v. Ohio)
- jbapple 12y agoIt was "White son of a bitch, I'll kill you", and it was Gooding v. Wilson.
- eurleif 12y agoAnd as far as I can tell, it wasn't that what he said was constitutionally protected. It's that the statute he was charged under was unconstitutionally broad, because it prohibited "abusive language" in general. A more specific statute, prohibiting only threats, would have likely been ruled constitutional.
- jbapple 12y agoI'm not sure about "likely", but upon a closer reading, I agree that the Gooding decision looks like it was mainly about the broadness of the statute. Thanks for noting that.
- higherpurpose 12y agoIt's interesting that you say his sentence was "unjust" given that you always seem to defend crazy sentences as "not being the real ones anyway". Also those three sound like incredibly weak charges, and yet you somehow defend the prosecution over them.
- tptacek 12y agoIs it because I say his sentence was unjust given that me always seem to defend crazy sentences as not being the real ones anyway that you came to me? Earlier you said I say his sentence was unjust given that me always seem to defend crazy sentences as not being the real ones anyway? Maybe your life has something to do with this.
- downandout 12y ago>The offense tied to Brown's "linking" was dismissed This masks the scary reality that someone was indicted, arrested, and prosecuted for posting a link (not to mention that it was dismissed as part of a plea - not for lack of legal merit). While in this case there were other charges as well, there didn't have to be - all of the same pre-trial horrors (including possible detention without bail) could have occurred with only that charge. The fact that such a charge may eventually be dismissed/beaten at trial after your life is burnt to the ground for posting a link is little comfort.
- tptacek 12y agoThat's also a misleading way of framing the issue. Brown wasn't charged with "criminal linking" (an offense that does not exist). He was charged with deliberately and knowingly assisting in the breach of Stratfor, and subsequent maximization of the damage from that breach. And remember, he was convicted of doing that; they just pursued a different vector for it than the link. Keep in mind also, they didn't just work back from people who posted links. Hector Monsegur ratted Brown out. Most criminal statutes look insane if you ignore the mens rea component and consider only the actus reus. Probably the right way to address your comment is to acknowledge the sentiment behind it. It would be ominous if prosecutors trawled the Internet looking for the wrong kinds of links --- people RT'ing updates from Anonymous, for instance, or relaying already-public newsworthy facts from breaches --- and fit accessory liability cases around those innocuous acts. It is worth being wary about prosecutors doing that, because computer crime laws are poorly rigged and set up terrible incentive systems for prosecutors. It's just that those concerns are not yet vindicated by the Brown case.
- downandout 12y agoWhile "criminal linking" doesn't exist as a standalone crime, prosecutors have essentially tried to make it exist via other statutes. I don't know the disposition of the case, but a man in the UK was ordered a few years ago to be extradited to the US to stand trial for criminal copyright infringement after operating a site that offered links to copyrighted sports broadcasts [1]. In the Brown case, they tried to use the conspiracy statutes. In both of the above examples, while not charged with "criminal linking," the actual conduct was linking to something prosecutors didn't like. The loud and clear message they are sending is "link to things we don't like, and we'll find a way to get you". That will have a chilling effect on free speech. [1] http://www.theguardian.com/law/2012/jan/13/piracy-student-loses-us-extradition http://www.theguardian.com/law/2012/jan/13/piracy-student-lo...
- camhenlin 12y agoMan, I hope my password isn't in there.
- deleted 12y ago[deleted]
- untog 12y agoRead the actual article. None of this data is new: All data currently is or was at one time generally available to anyone and discoverable via search engines in a plaintext
- chisleu 12y agoI'm not! #successkid
- m8urn 12y agoActually three of my own passwords are on there, I left them in
- deleted 12y ago[deleted]
- aceperry 12y agoMy thoughts exactly. I'm amazed that I can download the file, but at least I get to see if any of my passwords are there.
- cwarrior 12y agoWhat's your password? I could check the file to see if it's there. I found one of mine. Does anybody know from where these passwords are from?
- m8urn 12y agoPublic dumps mostly from the last 5 years, but some as old as ten years
- stephentmcm 12y agohunter2
- 20kleagues 12y agoWay to go buddy! This research is indeed necessary and releasing such a dataset will be beneficial. Maybe it will also bring light to how outdated password based authentication really is.
- julianpye 12y agoEveryone knows the whole email/password concept is broken. I believe that overall OAUTH is needed, but it needs a much stronger consumer facing view.
- sarciszewski 12y agoA well-implemented OAuth implementation is wonderful. Sadly, many implementations are just crappy.
- throwawaykf05 12y agoWhat's worse than crappy implementations is that every provider has their own version of implementation-specific crappiness that is inconsistent with everyone else's.
- StavrosK 12y agoI'm not sure how OAuth can help. Does it allow you to choose whom to authenticate with, or does it tie you to one specific provider? I much prefer Persona, but Mozilla has abandoned it, and most resources around it are dead links. What a colossal shame.
- sarciszewski 12y agoI'm personally looking forward to something like SQRL. https://www.grc.com/sqrl/sqrl.htm https://www.grc.com/sqrl/sqrl.htm
- StavrosK 12y agoThat's also a nice protocol, but I think it requires too many extra things (mobile phone, net connection, etc). Plus, what if your key gets stolen?
- function_seven 12y agoIt doesn't require a mobile phone. A client on your desktop can handle the authentication. There's also a mechanism[1] to change your master key should it become compromised. Looks like a huge drawback is that it requires you to store an offline "Identity Unlock Key" somewhere. [1] https://www.grc.com/sqrl/idlock.htm https://www.grc.com/sqrl/idlock.htm
- sarciszewski 12y ago> He was close to Anonymous and was in fact their spokesman. Err, no he wasn't. He just managed to get a modest amount of attention.
- charlespwd 12y agoFor the lazy: grep -i <password> 10-million-combos.txt
- flavor8 12y agoAnd then history -c
- vacri 12y ago... which will clear your entire history, which you probably don't want. I don't know a shorter way, but to delete one line from history, do 'history', which shows the line numbers, then 'history -d LINE_NUM'. Or, in bash, prepend the command with a space and it won't go into history.
- akerl_ 12y agoOpen new terminal -> unset HISTFILE -> do your greping -> close terminal
- fletchowns 12y agoUnless somebody did a ps while your grep was running... Don't put sensitive stuff in CLI args!
- loqi 12y agoGood point, how about grep -f - 10-million-combos.txt <password> ^D^D
- brianshaler 12y agoDepending on your system and configuration, couldn't you prepend a space to the command to prevent it from being saved into your history? edit: Looks like vacri mentioned this in a peer comment an hour ago. Whoops!
- nmjohn 12y ago
- stevecalifornia 12y agoWhen I first got on the Internet in 1994 I used the same password for everything for the next decade before I became security conscious (now I have a random, strong, unique password for every service). Anyways, that password is not in this list. I have found it in other password dumps before. So, I don't know what to think.
- 6t6t6 12y agoI don't think it is necessary to have one password for every single system, but three or fours tiers of passwords. And just keep in mind that there's one password to "rule them all". That is the password for the primary mail account. I use 2-factor authentication for that.
- scintill76 12y ago> three or fours tiers of passwords Can you elaborate? My first thought is tiered by category of the service. No, I don't want my financial institutions to all have the same password, even if it's from the most secure tier.
- pdenya 12y agoSites require you to sign up but it won't matter much if someone gains access to your account on them. Those might as well share a password. Same with sites that share trust buckets like [goodreads, yelp], [facebook, twitter] etc. In the real world though just memorize separate bank and email passes and use a password manager w/generated passwords for everything else.
- nostromo 12y agoThis isn't a comprehensive list of all leaked passwords. It's a random subset of 10 million for research purposes.
- Buge 12y agoThis is 10 million out of 1 billion that he has. So there is only a 1% chance of a leaked account getting in this list.
- meowface 12y agoI don't understand exactly why it's necessary to release usernames along with the passwords, or why it's ethical to do so. Stripping the domain portion of email addresses does absolutely nothing when you can find the real email, and other accounts of the victim, by Googling the unique part of the email address. How does tying each password to its corresponding username help with password research, and does the value gained outweigh the cost of someone using this list for malicious purposes? I'm not saying this should be illegal, but I'm struggling to understand the intent here.
- detaro 12y agoProbably to find out how many people do stuff like type their username backwards as a password/what kind of patterns they use. If that is useful enough information to warrant publishing data like this is debatable, yes.
- exogen 12y agoAlso interesting, how features of a username might correlate with password strength. Who do you think uses a stronger password, someone with the username "carguy551978" or someone with the username "w1ntermute"?
- swatow 12y agocarguy followed by the 24'th n such that 1 + n + n^13 is prime, followed by the 34'th such n? I would expect a very, very strong password from someone who picks their username like that. (see https://oeis.org/search?q=__%2C+551%2C+__%2C+978&sort=&language=&go=Search https://oeis.org/search?q=__%2C+551%2C+__%2C+978&sort=&langu...)
- Intermernet 12y agoYou will like this: http://www.njohnston.ca/2009/06/11630-is-the-first-uninteresting-number/ http://www.njohnston.ca/2009/06/11630-is-the-first-uninteres...
- 12y ago
- dj-wonk 12y agoForgive me for doing so, but allow me to ask some possibly ignorant questions and perhaps play the devil's advocate for a moment. What about this release will help? What are the compelling research problems in the space? We know users pick bad passwords. It seems to me the most compelling "problem" is hardly a research question -- isn't it about finding ways to encourage users pick strong passwords, not share them between sites, and not put them on sticky notes on their monitors. Ok, putting my charitable hat again... My best guess is that researchers would like some idea about how long it takes to crack some percentage of accounts; e.g. with rainbow tables or other techniques? The author mentioned "Analysis of usernames with passwords is an area that has been greatly neglected and can provide as much insight as studying passwords alone." What directions might a researcher take this?
- m8urn 12y agoThe main reason I have always included usernames and passwords in my research is because it allows me to analyze frequency data across multiple sites. Although I could have anonymized the usernames, I thought it would be best to keep them in. There is good value there. For example, there is quite a bit of overlap between usernames and passwords. Also, how many users include all or part of their usernames in their passwords. Plus, what usernames might hackers be most likely to try out? The main goal here is to put the data out there and let other researchers find the value in it.
- pbreit 12y agoSo how would you utilize such knowledge in the real world?
- tfinniga 12y agoYou could use it to create a password strength meter for your website, and enforce a certain strength. Let's say it is common to include a subset of the username in passwords. Doing so would decrease the password strength and be disallowed. Also, you could look at certain usernames and compute likelihood of certain dictionary words, and disallow them. For example, a user named Bob might be unlikely to use spanish words in a password, but a user named Jose might be more likely. Being aware of methods/info used by crackers when designing secure systems will lead to stronger systems.
- failed_ideas 12y agoThis is great, but if you use a password manager, it's very difficult to determine which, if any, of your accounts would be compromised. For myself, this would just be doing a dump and looping a few greps. But for family and friends, does anyone have any ideas for a less technical audience?
- jpatokal 12y agoIf you're using a password manager and thus -- I hope -- using a different password for every service, it doesn't really matter if one service gets compromised. The compromised service in question will (hopefully) force password resets for all affected users, and the compromised password is useless elsewhere.
- querulous 12y ago1password has a limited ability to warn you of compromised passwords. they maintain a database of breaches that they warn you about in their client. the warning, however, is much less prominent than it probably should be
- saraid216 12y agoInstead of responding to breaches, I would recommend an annual (more frequent is better, obviously, but I think annual is fine) cycle of rotating passwords. Just pick a day and spend it replacing passwords. As a side effect, you get a mental update on exactly what identities you're managing and whether or not you want to modify or close them. This should be fairly straightforward even for non-technical people, if they've got a grasp on actually using the password manager itself. The hard part is (1) getting the list of identities, which isn't too hard if you're hand-holding, and (2) actually remembering to do it. (Which is why annual is nice. You can peg it to a holiday you already celebrate, or substitute it for one you don't. Halloween, for instance, because breaches are scary? Or something.) Bonus: if a breach happens that actually feels scary, just do the rotation ritual ahead of time. Not that big of a deal.
- forgotX2 12y agoCould someone describe the dataset for me? Is it just two columns with one for usernames and another for passwords? Or is there any other info included? I'm on mobile right now or else I'd grab it myself.
- rinon 12y agoyep, just 2 columns
- m8urn 12y agoThe first column is username, followed by a tab, followed by the password.
- elchief 12y agoKnow what encoding it's in? Postgres is choking on UTF8 and Latin1
- marksomnian 12y agoAre you sure it's not choking just because it's postgres?
- Kenji 12y agoI could be relieved that my favourite password isn't in there but it's already been leaked by stupid, stupid engineers working for Riot (League of Legends video game) who stored it in plaintext and a hacker got it. It is a good practice to regularly change passwords anyways: If you're worried that your password is in there, you're doing it wrong in the first place.
- ssully 12y agoYou're doing it wrong if you have a favorite password. Use a password manager; there are more then a handful out there that are multiplatform and easy to set up. If that isn't your thing then there are plenty of techniques for generating unique, easy to remember passwords.
- jrochkind1 12y ago> As a final note, be aware that if your password is not on this list that means nothing. This is a random sampling of thousands of dumps consisting of upwards to a billion passwords. Please see the links in the article for a more thorough check to see if your password has been leaked. Or you could just google it.
- jacobsimon 12y ago_ everyone frantically searches for their own usernames _
- LeoPanthera 12y agoFun! $ export LC_ALL='C' $ awk '{ print $2 }' 10-million-combos.txt | tr 'A-Z' 'a-z' | sort | uniq -c | sort -nr | head -n 20 55893 123456 20785 password 13582 12345678 13230 qwerty 11696 123456789 10938 12345 6432 1234 5682 111111 4796 1234567 4191 dragon 3845 123123 3734 baseball 3664 abc123 3655 football 3330 monkey 3206 letmein 3136 shadow 3126 master 3050 696969 3002 michael Edit: I used Wordle[1] to make a wordcloud of the top 1000 passwords: http://i.imgur.com/FImcPiG.png http://i.imgur.com/FImcPiG.png [1]: http://www.wordle.net http://www.wordle.net
- userbinator 12y agoIn other words, supposing that this data is representative of most peoples' password practices, just trying these 20 passwords gives you a ~18% success rate for any username. And... dragon. That's an unusual password to make the top-10 list. I think this might be a somewhat skewed sampling.
- crisnoble 12y agoIt makes no sense to me, but I do recall a middle school phase where I used either "dragon" or "drag0n" for my passwords. I didn't particularly even like dragons and I don't recall ever hearing others use it, so it really catches me by surprise. Whenever I see it in a top passwords list I am filled with memories of after school library trips.
- pgwhalen 12y agoIt makes equally little sense to me, but "dragon" is routinely high on top password lists.
- jessaustin 12y agoThat many people have noted the "dragon" phenomenon as strange, but we don't yet have an explanation, is perhaps stranger yet. In early days, one could have hypothesized that some basic "how to use passwords" resource had offered "dragon" as an example of a password, but after two decades of internet it seems unlikely that something like that could have had such a large effect.
- totony 12y agoFrom the law quoted in the article, wouldn't it be illegal to simply make a course about computer security? The teacher willfully (and knowingly) teaches the student about "possible means of access to a protected computer." Note: According to http://www.law.cornell.edu/uscode/text/18/1029 http://www.law.cornell.edu/uscode/text/18/1029 teaching is defined as trafficking information ("the term “traffic” means transfer, or otherwise dispose of, to another, or obtain control of with intent to transfer or dispose of; ")
- bikamonki 12y agoIt seems very useful for research and also practical uses, like how about a REST API with this dump? get <password> will not only return true if it exists but how common and how weak it is, or will return a false for unique. Is there such a service out there?
- lumpypua 12y agoGo make it! :)
- akerl_ 12y agoThis seems a bit like testing if your parachute was packed properly by deploying it. Once I've sent my password at a 3rd party API, it doesn't much matter what the API says: my password is no longer secure.
- bikamonki 12y agoCorrect, but every site where you signup does that and I do not think anyone cares. Maybe such API will not be for end users but for other apps to run signup forms against it and help users choose a better one. In any case, the whole password deal is broken. I now use my own offline pwd generator for the "important" sites but I guess I am not the average Internet user.
- akerl_ 12y agoWhat site out there is sending my plaintext passwords to a 3rd party service to validate their strength?
- avid8 12y agoEven if this release has no implications for security, I think it may raise legitimate concerns for users' privacy. No doubt most users expect that their passwords will be known only to themselves. Many of the usernames contain real names, and many more could probably be traced to them. Ian Watkins was found to have "gloated" about his crimes in his password. With time and attention, I wonder whether such "dark secrets" could be found in this list.
- deleted 12y ago[deleted]
- uptown 12y agoHow are things like Twitter accounts hacked? Are they generally brute-forced with a list like this, or how do so many of them get compromised?
- gayprogrammer 12y agoWoah you are REALLY optimistic about law enforcement agencies wanting to focus on real criminals. But Barrett Brown is not the first or only example. Aaron Swartz is the only example I need to understand what to expect from the various US law enforcement agencies.
- nyolfen 12y agoit's kind of hilarious that it takes a case as transparently self-serving as aaron swartz to calcify a population as privileged and inured to the justice system as programmers to go "woah hey this shit might be kind of fucked up!!!"
- ternaryoperator 12y agoAaron S. was not at all the first time programmers recognized the problem and acted on it. Perhaps it was the first time that you became aware of the issue. But there were large-scale campaigns as far back as Robert Morris's worm in 1988. Even then, programmers were rightly concerned with unfair punishment for hacking and were outspoken about their concern. Similarly, with the Randal Schwartz in 1995, and many times since.
- ryanlol 12y agoBarrett Brown intentionally did everything in his power (including, but not limited to publicly threatening named FBI agents and their families) to get targeted by LE, and succeeded. Swartz? Swartz knowingly did several obviously illegal things (breaking-and-entering?) and then acted shocked when he got charged. His actions may have been morally defensible, but not legally. Law enforcement did their job there.
- vaibhavmule 12y agoIs your password and username in that list?
- deleted 12y ago[deleted]
- zaroth 12y agoThere is an annual 'Passwords' conference [1], which I attended in 2012, and was blown away by quite how much researchers are able to do with these password lists. Unfortunately, I was equally impressed with what attackers are able to do with them as well. An important point is that attackers tend to have better lists, because they are the ones stealing and cracking them, and these lists make them increasingly better at cracking passwords. Defenders use the lists for all sorts of analysis on how exactly users pick passwords. For example, "complex password policies" have become increasingly popular. But do they actually increase the entropy of the chosen passwords? Surprisingly little, since users will "defeat" the policy by applying easy to guess "munging rules". Humans being human and such. The thieves have the lists, and learn to apply the munging rules and defeat the policies. Researchers need these lists so they can discover the same weakness and try to react. More recent research looks at things like how effective the password strength indicators are at actually helping users choose stronger passwords. We also learn about how users choose different strength passwords based on the sites they visit and such. This is absolutely fertile ground for research which can improve how we perform authentication. Yet another good use of the lists is in defending against online attacks. E.g. Failed attempts that follow the general probability distribution of the lists are easier to identify as bots. [1] - I think all the talks are posted, although I'm not sure there's a central archive, each conference is identified as Passwords^[Year], e.g. Passwords^14 https://passwordscon.org/ https://passwordscon.org/
- pbreit 12y agoI'd be curious at what researchers were able to do with such a list (genuine, practical advances). It doesn't strike as particularly useful.
- zaroth 12y agoNot a bad place to start: http://passwords14.item.ntnu.no/program.php http://passwords14.item.ntnu.no/program.php
- meric 12y agoThese lists were released by attackers in the first place. Attackers are always going to have the lists, and the only choice defenders can take is whether to use and distribute to the defender community, or not.
- deleted 12y ago[deleted]
- igonvalue 12y agoIs there an http download link that would allow downloading from the browser (or with curl)?
- rplnt 12y agoThere are services that will download a torrent for you. This one worked for me without registration http://www.direct-torrents.com/ http://www.direct-torrents.com/
- yeukhon 12y agohttp://security.stackexchange.com/questions/46625/is-it-legal-to-publish-viticims-password-and-email http://security.stackexchange.com/questions/46625/is-it-lega... I thought of exactly the same. I was motivated by the password strength meter out there. How can you actually tell a password is strong or not or whether a password is known to attacker or not if you can ask (I was thinking along the line of private information retrieval) privately and get a probability rather than a yes/no based on all the known stolen credential out in the Internet (there are many Gbs files you can download)...
- sandworm 12y agoIt was a mistake to release this today. Everyone knows that legally questionable moves should always be made on a friday. That allows everyone in government to cool down for a couple days. By the time the weekend is over all the news outlets have moved on to whatever war just started up. You don't want some hothead prosecutor tweeting out a threat, forcing himself to follow through later in the week. Nobody picks a fight when 15 minutes away from a weekend. Watch the NSA/CIA/MIB admissions. They always stage their spying/torturing me culpas on friday afternoons.
- naradaellis 12y agoIn the show West Wing they called it taking out the trash.
- srcole 12y agoWhat sorts of analyses are you guys planning? Maybe: -clustering of passwords. are aspects of the username biased towards certain clusters? -distribution of alphanumeric characters at each position of a password (e.g. 1 is a disproportionately common final character) -differences in password strength between usernames with male and female names
- hueving 12y agoI wish there was an origin with these. A username/password combo I use on a ton of sites I don't care about is on here. It would be nice to know which is one leaked it.
- ttty 12y ago>Many companies, such as Facebook, also monitor public data dumps to identify user accounts in their user base that may have been compromised and proactively notify users. That is smart!
- deleted 12y ago[deleted]
- jcm1317 12y agoHunter6 is used as a password 9 times...
- jammycakes 12y agoJust a thought here. As far as I can tell, many bona fide security researchers seem to be independent consultants. Would they be less at risk of prosecution if they were handling sensitive data such as user names and passwords under the coverage of universities and/or similar accredited institutions operating under protocols as to who can and cannot access the data? It would probably be more security theatre than actual security, but I'd imagine that it would at least keep the FBI happy.
- osw 12y agoawk '{ print $2 }' 10-million-combos.txt | grep 1234 | wc -l only 180896 people have 1234 in their password, thought there would be more
- levlaz 12y agoIf anyone wants to check their username, I have a searchable DB up now. https://levlaz.org/passwords https://levlaz.org/passwords
- tomkinstinch 12y agoTo save a moment of time, here's a quick check that won't save the password string to your command history: read -e -s -p "Password: " password && grep -i $password 10-million-combos.txt | wc -l && password=""
- ommunist 12y agoI thank the post author for releasing this data. I found one of my accounts there and changed password to a more secure one.
- pp19dd 12y agoWent ahead and performed a Levenshtein distance analysis from this list, and made a graph of it. Number 8 seems to be the sweet 'secure' spot that most people latch onto, though the distribution curve is interesting - or very human-like: http://pp19dd.com/2015/02/levenshtein-distance-10-million-usernames-passwords/ http://pp19dd.com/2015/02/levenshtein-distance-10-million-us...