o00o Posted September 2, 2016 Report Share Posted September 2, 2016 nobody uses this anymore right? still some of you might have old accounts there: Quote Crikey: 43,570,999 user accounts were breached in a hack of Last.fm that occurred in March of 2012, according to a report from LeakedSource. Three months after the breach, in June of 2012, Last.fm issued the following statement: “We are currently investigating the leak of some Last.fm user passwords. This follows recent password leaks on other sites, as well as information posted online. As a precautionary measure, we’re asking all our users to change their passwords immediately.” The number of passwords and the severity of the hack were not uncovered until today. The passwords were stored using unsalted MD5 hashing. Rather than storing passwords in plaintext, nearly every site that stores critical user information utilizes some form of hashing. Hashing is a method for encrypting data, but some methods are far superior to others. MD5 is seriously out of style, in part because it is not mathematically intensive enough to resist modern methods of brute-force cracking. Moreover, Last.fm didn’t use salt in its hashing process. Salting is the practice of adding a random string of numbers to the hash for each individual password, making them more secure and decreasing the likelihood that they will be cracked if the passwords are ever leaked online. Unfortunately, Last.fm did not take that step, and LeakedSource reports that most of the passwords were easily cracked. For the second time this week, our advice is that you change your password immediately if you have an account on Last.fm. The most popular password pulled from the Last.fm database was 123456. Seriously, it’s 2016 people — use a platform like LastPass to generate randomized, complex passwords that are unique to every service for which you sign up. https://techcrunch.com/2016/09/01/43-million-passwords-hacked-in-last-fm-breach/ Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide o00o's signature Hide all signatures Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/ Share on other sites More sharing options...
azatoth Posted September 2, 2016 Report Share Posted September 2, 2016 i been wondering about using a password manager, but i am looking for a free non-intrusive program that works on phone, windows and ubuntu and also works when logging in on public computers. basically i have no idea how they work and need suggestions. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide azatoth's signature Hide all signatures last.fm the biggest illusion is yourself Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477572 Share on other sites More sharing options...
Herr Jan Posted September 2, 2016 Report Share Posted September 2, 2016 Had to double check but I deleted my last.fm account(s) some years ago but that might've been after 2012... Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477583 Share on other sites More sharing options...
mcbpete Posted September 2, 2016 Report Share Posted September 2, 2016 On 9/2/2016 at 9:49 AM, azatoth said: i been wondering about using a password manager, but i am looking for a free non-intrusive program that works on phone, windows and ubuntu and also works when logging in on public computers. basically i have no idea how they work and need suggestions.Bizarrely it seems like the most secure way to store passwords nowadays is to just write them on a piece of paper that you keep with you .... Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures I haven't eaten a Wagon Wheel since 07/11/07... ilovecubus.co.uk - 25ml of mp3 taken twice daily. Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477584 Share on other sites More sharing options...
Guest Posted September 2, 2016 Report Share Posted September 2, 2016 this probably hasn't been updated for the last.fm thing yet, but it's pretty useful: https://haveibeenpwned.com I've been guilty of re-using a weak default password on multiple sites in the past, several of these show up as breached if I enter my email addresses into the site above. Pretty sure there are still multiple old logins to various sites flying around where one would just need to copipasta the credentials... Using iCloud keychain now, it's a pretty minimal & neat password manager which is integrated nicely into Safari & syncs across devices. Quote Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477590 Share on other sites More sharing options...
Kennylogg Bubblebath Posted September 2, 2016 Report Share Posted September 2, 2016 I still scrobble but don't really use the site itself anymore. Quote MD5 is seriously out of style, in part because it is not mathematically intensive enough to resist modern methods of brute-force cracking. Moreover, Last.fm didn’t use salt in its hashing process. Salting is the practice of adding a random string of numbers to the hash for each individual password, making them more secure and decreasing the likelihood that they will be cracked if the passwords are ever leaked online. Unfortunately, Last.fm did not take that step, and LeakedSource reports that most of the passwords were easily cracked. Can't say this really surprises me. The Last.fm devs are notorious for being a lazy bunch of cunts. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477593 Share on other sites More sharing options...
usagi Posted September 2, 2016 Report Share Posted September 2, 2016 old news. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide usagi's signature Hide all signatures On 4/17/2013 at 2:45 PM, Alcofribas said: afaik i usually place all my cum drops on scientifically sterilized glass slides which are carefully frozen and placed in trash cans throughout the city labelled "for women alco" with my social security and phone numbers. Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477599 Share on other sites More sharing options...
Bechuga Posted September 2, 2016 Report Share Posted September 2, 2016 Oh man, I hope someone doesn't crack my password and retag all my scrobbles! That said, why AM I still scrobbling what I listen to? It's the nearest I come to some kind of OCD. Should prob just delete it. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide Bechuga's signature Hide all signatures Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477630 Share on other sites More sharing options...
joshuatxuk Posted September 2, 2016 Report Share Posted September 2, 2016 On 9/2/2016 at 9:49 AM, azatoth said: i been wondering about using a password manager, but i am looking for a free non-intrusive program that works on phone, windows and ubuntu and also works when logging in on public computers. basically i have no idea how they work and need suggestions. same here. I actually use lastfm still but spotify has really taken over my need for it recommendation wise. I'd like to archive my scrobbles though...is there a way to do that? Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide joshuatxuk's signature Hide all signatures Tape Escape! Aural Canyon Wood Between Worlds Tapes [joshuatxuk-is-dead] Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477633 Share on other sites More sharing options...
maitake Posted September 2, 2016 Report Share Posted September 2, 2016 (edited) A lot of people like LastPass, but I use KeepassX. I keep it along with the database file on my dropbox. The db has an extremely strong passphrase but the dropbox uses one of my old and easy to remember passwords. Someone could compromise the account but would never get access to the keepassx db. All passwords are randomly generated with alphanumeric characters, numbers, and symbols (as long as the site it's for allows symbols). Most are around 30 digits long. For phone, I use an app that can open keepass kdb files. There's a plugin for keepass that can autofill the passwords into forms but I don't bother. Just as easy to copy/paste when I need them.. Edited September 2, 2016 by maitake Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477648 Share on other sites More sharing options...
Bechuga Posted September 2, 2016 Report Share Posted September 2, 2016 Use words that no-one would associate with you > spell words backwards > replace certain letters with numbers / symbols = uncrackable Also I've used variations on the same password since high school but modified and mutated every time I need a new one. It's evolved to this strange form I can never forget but seems to be--so far--uncrackable and impossible to guess. Not that I have anything worthwhile to be stolen... On 9/2/2016 at 11:13 AM, mcbpete said: On 9/2/2016 at 9:49 AM, azatoth said: i been wondering about using a password manager, but i am looking for a free non-intrusive program that works on phone, windows and ubuntu and also works when logging in on public computers. basically i have no idea how they work and need suggestions.Bizarrely it seems like the most secure way to store passwords nowadays is to just write them on a piece of paper that you keep with you .... Or tattoo them on the inside of your eyelids Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide Bechuga's signature Hide all signatures Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477651 Share on other sites More sharing options...
BUNKUM Posted September 2, 2016 Report Share Posted September 2, 2016 (edited) Damn, I still use Last.fm but, like Bechuga above, I don't really know why, I don't use anything besides scrobbling. I also pay for Last Pass, really couldn't do without it nowadays. Edited September 2, 2016 by BUNKUM Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide BUNKUM's signature Hide all signatures Grid Pattern Last.fm Discogs Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477656 Share on other sites More sharing options...
mcbpete Posted September 2, 2016 Report Share Posted September 2, 2016 On 9/2/2016 at 4:12 PM, BUNKUM said: I also pay for Last Pass, really couldn't do without it nowadays.I remember a while ago I was gonna do the same and then this happened so I decided against any password managers Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures I haven't eaten a Wagon Wheel since 07/11/07... ilovecubus.co.uk - 25ml of mp3 taken twice daily. Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477660 Share on other sites More sharing options...
BUNKUM Posted September 2, 2016 Report Share Posted September 2, 2016 On 9/2/2016 at 4:19 PM, mcbpete said: On 9/2/2016 at 4:12 PM, BUNKUM said: I also pay for Last Pass, really couldn't do without it nowadays.I remember a while ago I was gonna do the same and then this happened so I decided against any password managers Ah yes, I remember that. Changed my master password straight away and not had any issues with it since. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide BUNKUM's signature Hide all signatures Grid Pattern Last.fm Discogs Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477662 Share on other sites More sharing options...
maitake Posted September 2, 2016 Report Share Posted September 2, 2016 That's why I decided against lastpass and use keepassx instead. I'd feel comfortable sending my .kdb file to any willing hacker. They'll never get in. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477676 Share on other sites More sharing options...
caze Posted September 2, 2016 Report Share Posted September 2, 2016 On 9/2/2016 at 4:19 PM, mcbpete said: On 9/2/2016 at 4:12 PM, BUNKUM said: I also pay for Last Pass, really couldn't do without it nowadays.I remember a while ago I was gonna do the same and then this happened so I decided against any password managers Enpass, and I'm sure others, allow you to store the db locally, or on one of your own cloud drives. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477679 Share on other sites More sharing options...
Guest Posted September 2, 2016 Report Share Posted September 2, 2016 in case this isn't clear - it's not about someone having access to your last fm account, but about there now being another huge database of passwords to be used in dictionary attacks on other sites. this helps crackers crack other, more important accounts. watch these two videos: use a pw manager, change all ur passwords to strong ones. otherwise you gonna get pwnd sooner or later Quote Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477681 Share on other sites More sharing options...
maitake Posted September 2, 2016 Report Share Posted September 2, 2016 yeah, it's pretty remarkable how many people out there use the same pass for nearly every account. fucking crazy people. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477683 Share on other sites More sharing options...
marf Posted September 2, 2016 Report Share Posted September 2, 2016 (edited) and im going to have a robot operate on me and a driverless car. no thank you.. id rather not some russian hacker infiltrate my conolonoscpy Edited September 2, 2016 by marf Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477685 Share on other sites More sharing options...
mcbpete Posted September 2, 2016 Report Share Posted September 2, 2016 On 9/2/2016 at 5:38 PM, marf said: russian hacker infiltrate my conolonoscpyNew Venetian Snares album title confirmed ! Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures I haven't eaten a Wagon Wheel since 07/11/07... ilovecubus.co.uk - 25ml of mp3 taken twice daily. Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477686 Share on other sites More sharing options...
Guest WNS000 Posted September 2, 2016 Report Share Posted September 2, 2016 On 9/2/2016 at 5:17 PM, phling said: in case this isn't clear - it's not about someone having access to your last fm account, but about there now being another huge database of passwords to be used in dictionary attacks on other sites. this helps crackers crack other, more important accounts. watch these two videos: use a pw manager, change all ur passwords to strong ones. otherwise you gonna get pwnd sooner or later Thank you very much for the videos. Very interesting and sobering indeed. I have learned something today. Quote Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477697 Share on other sites More sharing options...
Joyrex Posted September 2, 2016 Report Share Posted September 2, 2016 For the new forum I am thinking about implementing strong passwords and two-factor authentication... Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures Follow WATMM on Twitter: @WATMMOfficial Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477698 Share on other sites More sharing options...
Guest WNS000 Posted September 2, 2016 Report Share Posted September 2, 2016 ^ nice Quote Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477702 Share on other sites More sharing options...
chenGOD Posted September 2, 2016 Report Share Posted September 2, 2016 1password is the shit. Works on Mac, Windows, Android and iOS. End-to-end encryption, choices of local or cloud storage. Pay for it - it's worth it. Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide all signatures 백호야~~~항상에 사랑할거예요.나의 아들. Shout outs to the saracens, musulmen and celestials. Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477712 Share on other sites More sharing options...
ghOsty Posted September 2, 2016 Report Share Posted September 2, 2016 People still use last.fm? Thanks Haha Confused Sad Facepalm Burger Farnsworth Big Brain Like × Quote Hide ghOsty's signature Hide all signatures Link to comment https://forum.watmm.com/topic/91433-43-million-passwords-hacked-in-lastfm-breach/#findComment-2477722 Share on other sites More sharing options...
Recommended Posts