It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
avatar
Foxhack: I got the user database to check on my account, and the password is there, encoded. But judging from the list of passwords included, the encryption wasn't very strong to begin with.
avatar
wpegg: you probably just made a slip, but I'd like to point out that encoded does not mean encrypted.

What I am confused about, is why number 4 of the password list (http://www.bbc.co.uk/news/technology-11998648) is lifehack. sounds a little fishy to me.
Yeah, I meant encrypted. Sorry about that, and thanks for the correction.

About the password... Gawker has a site named "Lifehacker". So maybe people who posted there used that password because it was easy to remember.
Post edited December 15, 2010 by Foxhack
Here's a good writeup of just what exactly went down. For the tldr folks, basically Gawker got itself in a pissing match with 4chan over the summer, and as part of this basically painted a big target on themselves. This seems to have got the attention of a group of blackhats (who claim they are not associated with either 4chan or anonymous) to take notice, and what followed was the result of that. On the security side of things there's a pretty long list of things Gawker did wrong, such as running severely out of date software on their servers, ignoring warning signs their internal systems had been compromised (it looks like they were actually compromised going all the way back to mid November), and waiting way too long to notify their users once they did realize data had been compromised. The passwords were encrypted, but still got out due to Gawker using DES to encrypt them (DES was cracked back in the late 90s). Basically a nice object lesson in how not to handle security.
avatar
Foxhack: About the password... Gawker has a site named "Lifehacker". So maybe people who posted there used that password because it was easy to remember.
Agreed. And you can guess what their passwords would be on other sites.
Me too. Still, changed it and it's all good.

Not too bothered by it but I see some extremely uninformed content in the OP.