create account

How not to be Mark Zuckerberg dumb about your passwords by dedmatvey

View this thread on: hive.blogpeakd.comecency.com
· @dedmatvey ·
$44.13
How not to be Mark Zuckerberg dumb about your passwords
A group of hijackers known as OurMine, possibly from Saudi Arabia, briefly took over Facebook chairman and CEO Mark Zuckerberg's Twitter and Pinterest accounts Sunday (June 5).

<center>http://a57.foxnews.com/images.foxnews.com/content/fox-news/tech/2016/06/06/how-not-to-be-mark-zuckerberg-dumb-about-your-passwords/_jcr_content/par/featured-media/media-0.img.jpg/876/493/1465245917164.jpg?ve=1&tl=1</center>

It turns out Zuckerberg was one of the 165 million LinkedIn members whose login credentials were in a recently leaked data dump dating from 2012. He apparently had reused his LinkedIn password — "dadada," according to the group that took over his Twitter account — across multiple accounts, and had never changed them.

Zuckerberg's mistake is one that too many people make. They pick a easy-to-remember password, and use it for more than one account. Fortunately, it's simple to be smarter than Mark Zuckerberg about online passwords.

- <b>Start by creating unique and complex passwords.</b> You may not want to spend that time and effort on creating a password for each and every account, but definitely use it for those that matter: online banking, email, social networks, online retailers and any other service that you trust with sensitive data.
- <b>Next, don't let your web browser store your login information for any website that involves sensitive data.</b> Doing so is fine if there's nothing sensitive to protect in a specific account, but make sure those "so what if they do get hacked" accounts have nothing more on you than a username and an email address.
- <b>Don't let websites retain your credit-card information, either</b> — you don't want that showing up in the next massive data breach. Typing information in every time you need to purchase may be less convenient, but it protects you in the long run.
- <b>Turn on two-factor authentication</b> on every site for which it's available.Twitter, Snapchat, Facebook, Microsoft, Amazon, Dropbox, LinkedIn, Yahoo, Google, Apple and many more offer this feature, which usually requires that you have access to your smartphone in order to log in from a new computer.
- <b>If you want to get really serious, sign up for high-value accounts with unique email addresses as well as unique passwords.</b> You'll have to remember a lot of email addresses, but your exposure during the next data breach will be minimal.
- <b>Consider using a password manager.</b> Most password managers let you log in from PCs, Macs, iPhones and Android phones alike, and many will create long, complex passwords for you. (But understand that keeping all your passwords in one place creates one centralized point of failure that attackers can target.)

Zuckerberg's "dadada" password wasn't stored as plaintext in the leaked LinkedIn database, but instead as a one-way hash created by running the password through a mathematical algorithm. The result is a string of characters that is theoretically impossible to reverse. In this case, "dadada" becomes "0f158e648228a19cab5f23acfd6c36f716a702a9".

The problem is that LinkedIn was lazy. It used the SHA-1 hash algorithm, which by 2012 was well understood to be vulnerable to reversing. Worse, LinkedIn didn't take any extra steps that would have strengthened the security, such as hashing the hash or "salting" the hash with extra characters. (Both are common practice, and LinkedIn began salting its hashes soon after the 2012 data breach.)

This made it easy for OurMine and any other bored ne'er–do–wells to reverse Mark Zuckerberg's password. Just [search "reverse SHA-1"](https://duckduckgo.com/?q=reverse+sha1&ia=qa) and you'll see there are plenty of options out there. Plug "0f158e648228a19cab5f23acfd6c36f716a702a9" into one and you'll get "dadada."

Original: [FoxNews](http://www.foxnews.com/tech/2016/06/06/how-not-to-be-mark-zuckerberg-dumb-about-your-passwords.html)
👍  , , , , , , , , , , , , , , , , , , , , , , , , , ,
properties (23)
authordedmatvey
permlinkhow-not-to-be-mark-zuckerberg-dumb-about-your-passwords
categorynews
json_metadata{"tags":["news","facebook","technology","funny"],"links":["https://duckduckgo.com/?q=reverse+sha1&ia=qa","http://www.foxnews.com/tech/2016/06/06/how-not-to-be-mark-zuckerberg-dumb-about-your-passwords.html"]}
created2016-06-08 04:38:18
last_update2016-06-08 04:38:18
depth0
children1
last_payout2016-08-12 21:42:12
cashout_time1969-12-31 23:59:59
total_payout_value22.064 HBD
curator_payout_value22.063 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length3,884
author_reputation4,753,753,353,368
root_title"How not to be Mark Zuckerberg dumb about your passwords"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id25,897
net_rshares21,588,682,421,624
author_curate_reward""
vote details (27)
@arhag ·
> He apparently had reused his LinkedIn password — "dadada," according to the group that took over his Twitter account — across multiple accounts, and had never changed them.

Wow... just wow.

> **Consider using a password manager.**

This is the best thing you can do if you want your passwords to actually be secure. 

Creating unique strong passwords for each website that you can actually remember is hard. You will either keep forgetting them or more likely you will start compromising the strength and/or uniqueness of the passwords so that you can actually remember them. Don't do this. Instead, use a password manager and let it generate and save the unique strong passwords for you. Then you only need to remember one strong password.

This is especially important for Steemit because attackers can brute-force your password all day long without any rate-limiting. If a hacker is targeting you specifically and your password is weak, they will eventually break it and permanently steal your account. So please, use a password manager. And it would be even better if you also use a separate randomly-generated owner key that you normally store offline.
👍  
properties (23)
authorarhag
permlinkre-dedmatvey-how-not-to-be-mark-zuckerberg-dumb-about-your-passwords-20160608t060025375z
categorynews
json_metadata{"tags":["news"]}
created2016-06-08 06:00:24
last_update2016-06-08 06:00:24
depth1
children0
last_payout2016-08-12 21:42:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,161
author_reputation52,490,827,205,383
root_title"How not to be Mark Zuckerberg dumb about your passwords"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id25,935
net_rshares670,649,415
author_curate_reward""
vote details (1)