<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Brits Give Up Passwords For a £5 Gift Voucher</title>
	<atom:link href="http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 14 Feb 2012 00:17:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: collector</title>
		<link>http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/#comment-124884</link>
		<dc:creator>collector</dc:creator>
		<pubDate>Thu, 02 Oct 2008 07:15:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1085#comment-124884</guid>
		<description>Go to any public user database and execute this:

SELECT password, count(*) FROM users
GROUP BY password
ORDER BY count(*) DESC;

you&#039;ll find that 1% of all hashed passwords are the same. Try to de-hash it width http://gdataonline.com/seekhash.php, or if you are using something other than standard md5, try hashing the 123456 and see if it&#039;s match ;)</description>
		<content:encoded><![CDATA[<p>Go to any public user database and execute this:</p>
<p>SELECT password, count(*) FROM users<br />
GROUP BY password<br />
ORDER BY count(*) DESC;</p>
<p>you&#8217;ll find that 1% of all hashed passwords are the same. Try to de-hash it width <a href="http://gdataonline.com/seekhash.php" rel="nofollow">http://gdataonline.com/seekhash.php</a>, or if you are using something other than standard md5, try hashing the 123456 and see if it&#8217;s match ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SpikyHead</title>
		<link>http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/#comment-124870</link>
		<dc:creator>SpikyHead</dc:creator>
		<pubDate>Wed, 01 Oct 2008 00:40:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1085#comment-124870</guid>
		<description>Well thats why they say... Common Sense is Not So Common...

When will these people learn</description>
		<content:encoded><![CDATA[<p>Well thats why they say&#8230; Common Sense is Not So Common&#8230;</p>
<p>When will these people learn</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yami King</title>
		<link>http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/#comment-124867</link>
		<dc:creator>Yami King</dc:creator>
		<pubDate>Tue, 30 Sep 2008 18:36:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1085#comment-124867</guid>
		<description>@ Darknet
You are correct about this, well... not entirely, as razta mentioned, you do really need evidence supporting that the information the user gives is actually correct.
--

But yes, people tend to give information away quite easily, but wasn&#039;t it already known to researchers, people like using information like dates of birth, their pet&#039;s name, etc... as their passwords?
What actually is quite funny too, is when company policies require users to change their password every month, but do not require any secure passwords, people tend to use the names of the current month as their password.</description>
		<content:encoded><![CDATA[<p>@ Darknet<br />
You are correct about this, well&#8230; not entirely, as razta mentioned, you do really need evidence supporting that the information the user gives is actually correct.<br />
&#8211;</p>
<p>But yes, people tend to give information away quite easily, but wasn&#8217;t it already known to researchers, people like using information like dates of birth, their pet&#8217;s name, etc&#8230; as their passwords?<br />
What actually is quite funny too, is when company policies require users to change their password every month, but do not require any secure passwords, people tend to use the names of the current month as their password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darknet</title>
		<link>http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/#comment-124859</link>
		<dc:creator>Darknet</dc:creator>
		<pubDate>Mon, 29 Sep 2008 07:30:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1085#comment-124859</guid>
		<description>They aren&#039;t giving actual passwords, but the survey mines enough data to ascertain the passwords within a few guesses and know WHICH sites they use them on. To most people they wouldn&#039;t even realise what they&#039;d given away.</description>
		<content:encoded><![CDATA[<p>They aren&#8217;t giving actual passwords, but the survey mines enough data to ascertain the passwords within a few guesses and know WHICH sites they use them on. To most people they wouldn&#8217;t even realise what they&#8217;d given away.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: razta</title>
		<link>http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/#comment-124858</link>
		<dc:creator>razta</dc:creator>
		<pubDate>Mon, 29 Sep 2008 07:02:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1085#comment-124858</guid>
		<description>I agree. I dont think many people would have given their real passwords, when they could just make it up and get the </description>
		<content:encoded><![CDATA[<p>I agree. I dont think many people would have given their real passwords, when they could just make it up and get the</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Goodpeople</title>
		<link>http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/#comment-124857</link>
		<dc:creator>Goodpeople</dc:creator>
		<pubDate>Sun, 28 Sep 2008 05:54:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1085#comment-124857</guid>
		<description>This is one of those moments where I wonder if people are really worh protecting.. 

Of course I would also have told the researcher that my passwords are very simple.. just to get the check.</description>
		<content:encoded><![CDATA[<p>This is one of those moments where I wonder if people are really worh protecting.. </p>
<p>Of course I would also have told the researcher that my passwords are very simple.. just to get the check.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2008/09/brits-give-up-passwords-for-a-5-gift-voucher/#comment-124855</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Sat, 27 Sep 2008 17:02:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1085#comment-124855</guid>
		<description>{sigh}
It&#039;s been said before, I&#039;d quite happily make up a password for a researcher. I&#039;d also tell them it was something simple, Wife&#039;s maiden name, pets name, registration number.
Why? I have a vested interest in generatin IT Sec work and fearmongering like that it just the ticket.
5 quid gift voucher would be a bonus for me.</description>
		<content:encoded><![CDATA[<p>{sigh}<br />
It&#8217;s been said before, I&#8217;d quite happily make up a password for a researcher. I&#8217;d also tell them it was something simple, Wife&#8217;s maiden name, pets name, registration number.<br />
Why? I have a vested interest in generatin IT Sec work and fearmongering like that it just the ticket.<br />
5 quid gift voucher would be a bonus for me.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

