• floofloof@lemmy.ca
    link
    fedilink
    arrow-up
    9
    ·
    edit-2
    3 months ago

    I managed to get in and change mine last night. So you just have to keep hammering that refresh button until you overcome whoever this asshole is that’s DOSing the site. Maybe even do it on several computers, and write a script to help.

    Edit: Joke, don’t do.

    • ChaoticNeutralCzech@feddit.org
      link
      fedilink
      arrow-up
      14
      ·
      3 months ago

      You’re contributing to the DDoS attack. Just wait, if your password is good enough and not in use elsewhere it should take a while to crack the hash.

      • imPastaSyndrome@lemm.ee
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        3 months ago

        This might be a silly question but it might not - if let’s say 5 (or even 50) people use the same username and password in multiple sites, and they have another site’s leak. Would they be able to easily crack the hash?

        • ChaoticNeutralCzech@feddit.org
          link
          fedilink
          arrow-up
          5
          ·
          3 months ago

          They will start a dictionary attack on the most common passwords and check their hashes against the stolen database. The speed depends on whether the password hashes obtained are salted in a known method (or not at all). If so, they can perform the dictionary search or brute force locally and VERY quickly.

          Take these charts with a grain of salt, they always depend on the attacker’s computing power. My password was generated with a password manager and it will take millenia to crack with a reasonable number of modern GPUs so I’ll be able to change it in time.

          If the method is not known, they will need to go through the servers, which have rate limits.

          The passwords are probably hashed with usernames so they can only attack one person at once but of course, once they have the plaintext password, they can use it anywhere else the user reused it or a variation of it.

          • psud@aussie.zone
            link
            fedilink
            arrow-up
            1
            ·
            3 months ago

            If the password hashes aren’t salted they can be cracked with a rainbow table - every password up to (whatever length the rainbow tables go up to now - 10 chars?) is easily cracked in seconds

            I expect Internet archive salts their password hashes.

            It doesn’t matter if the salting method is known, all salting methods are known and it’s easy to see what salt a password is hashed with as you need to know so you can hash a received password the same way for validation

        • Charzard4261@programming.dev
          link
          fedilink
          arrow-up
          3
          ·
          3 months ago

          Not a silly question! The answer is technically yes, but not really.

          Considering there are still sites that store plaintext passwords, there has to be some that just hash it and call it a day. For those, once you crack the hash, you know everyone with the same hash has the same password. Any real site does some more complex stuff to “personalise” each hashed password.

          The real issue is when you reuse the password and it gets cracked once, people will try that with your email for other leaks and live sites. If a lot of people use the same password (like “password123”), they’re likely to try it as one of the first guesses to crack any new leaks.

          I’m oversimplifying my already oversimplified knowledge of basic cryptography, but it’s a really interesting topic!