Hacker Newsnew | past | comments | ask | show | jobs | submit | 2012-06-06login
Stories from June 6, 2012
Go back a day, month, or year. Go forward a day, month, or year.
1.6.5 Million LinkedIn Password Hashes Leaked (translate.google.com)
561 points by ssclafani on June 6, 2012 | 511 comments
2.Make Better Select Boxes with Chosen (harvesthq.github.com)
514 points by tomschlick on June 6, 2012 | 83 comments
3.Fish: Finally, a command line shell for the 90s (ridiculousfish.com)
442 points by rjshade on June 6, 2012 | 146 comments
4.Take my money, HBO (takemymoneyhbo.com)
425 points by krogsgard on June 6, 2012 | 306 comments
5.Storing Passwords Securely (throwingfire.com)
250 points by pw on June 6, 2012 | 133 comments
6.LeakedIn (leakedin.org)
253 points by ams1 on June 6, 2012 | 174 comments
7.John Carmack is making a virtual reality headset (pcgamer.com)
244 points by otibom on June 6, 2012 | 63 comments
8.Buttons that morph out of the surface of the device. (tactustechnology.com)
225 points by jamesbritt on June 6, 2012 | 88 comments

Some observations on this file:

0. This is a file of SHA1 hashes of short strings (i.e. passwords).

1. There are 3,521,180 hashes that begin with 00000. I believe that these represent hashes that the hackers have already broken and they have marked them with 00000 to indicate that fact.

Evidence for this is that the SHA1 hash of 'password' does not appear in the list, but the same hash with the first five characters set to 0 is.

  5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8 is not present
  000001e4c9b93f3f0682250b6cf8331b7ee68fd8 is present
Same story for 'secret':

  e5e9fa1ba31ecd1ae84f75caaa474f3a663f05f4 is not present
  00000a1ba31ecd1ae84f75caaa474f3a663f05f4 is present
And for 'linkedin':

  7728240c80b6bfd450849405e8500d6d207783b6 is not present
  0000040c80b6bfd450849405e8500d6d207783b6 is present
2. There are 2,936,840 hashes that do not start with 00000 that can be attacked with JtR.

3. The implication of #1 is that if checking for your password and you have a simple password then you need to check for the truncated hash.

4. This may well actually be from LinkedIn. Using the partial hashes (above) I find the hashes for passwords linkedin, LinkedIn, L1nked1n, l1nked1n, L1nk3d1n, l1nk3d1n, linkedinsecret, linkedinpassword, ...

5. The file does not contain duplicates. LinkedIn claims a user base of 161m. This file contains 6.4m unique password hashes. That's 25 users per hash. Given the large amount of password reuse and poor password choices it is not improbable that this is the complete password file. Evidence against that thesis is that password of one person that I've asked is not in the list.

10.Hacking an ATM (henryschwarz.blogspot.co.uk)
203 points by rlpb on June 6, 2012 | 45 comments
11.Zeolite retains heat indefinitely, absorbs 4x more heat than water (extremetech.com)
178 points by ukdm on June 6, 2012 | 77 comments
12.The US Census now has an API (census.gov)
173 points by ams1 on June 6, 2012 | 38 comments
13.PostgreSQL when it is not your job (vanrees.org)
172 points by wahnfrieden on June 6, 2012 | 43 comments
14.Germany Increases 'You Are All Pirates' Tax On Solid State Media By 2000% (techdirt.com)
166 points by DiabloD3 on June 6, 2012 | 110 comments
15.I must be crazy (splinter.com.au)
150 points by chubs on June 6, 2012 | 118 comments
16.Samsung invests $500K in Linux Foundation to battle iOS (appleinsider.com)
149 points by dcesiel on June 6, 2012 | 48 comments
17.HN create account removed from login page (news.ycombinator.com)
143 points by leejw00t354 on June 6, 2012 | 58 comments
18.How Airbnb Earned Me $20,000 And A Restraining Order From My Landlord (fastcompany.com)
144 points by timjahn on June 6, 2012 | 137 comments

Again and again, people who use Airbnb to 'hack' the rental market get little sympathy from me when the chickens come to roost. If your landlord was interested in running a tenement home/boarding house/hotel, they wouldn't sign you into a year-long lease. Also, and I know this has been hashed out before on these comment threads but he's grossing $30k a year on the back of his landlord. The landlord has every right to be upset and take action.

The author of the post seems shocked that he's in violation of anything. Perhaps he'd like to share excerpts of his lease before he feigns such shock.

Come on, the guy lives alone in a 3+ bedroom apartment in Brooklyn. We all know he signed that lease specifically to run a pseudo-hotel business under the guise of an Airbnb profile. He whines that he can't afford to live in the New York rental market without roommates; so get roommates or move somewhere cheaper.

BTW, the author is a professional writer who (gasp!) has a brand new startup to plug.

edit: It sounds like this guy has a sincere love for the experiences and newfound social life he's found when acting as an ambassador for his city. His heart is in the right place. He would make a great Couchsurfing host and probably make even greater, long-lasting relationships.


Now there's a great idea! Provide your password to some random site purporting to check if your password's been compromised.
21.Pocket team's tips for aspiring Android developers: It’s not really terrifying. (getpocket.com)
100 points by stevestreza on June 6, 2012 | 27 comments
22.You half assed it. That is why your PhoneGap application sucks. (sintaxi.com)
96 points by sintaxi on June 6, 2012 | 110 comments

It's not pirating if you download Game of Thrones -- it's paying The Iron Price
24.Google Maps, Earth take on full 3D imagery (engadget.com)
89 points by alt_ on June 6, 2012 | 43 comments
25.Just Landed for iPhone helps you pick someone up from the airport. (getjustlanded.com)
88 points by jgrall on June 6, 2012 | 85 comments
26.LinkedIn’s iOS app transmits names, emails, and calendar notes, in plain text (thenextweb.com)
84 points by Kenan on June 6, 2012 | 40 comments

My favorite Ray Bradbury memory is the time he came to my school to talk about his books and ended up yelling at my English teach for trying to find hidden meaning that wasn't there just for the sake of busywork. RIP Mr. Bradbury.
28.What Makes Great Programmers Different? (drdobbs.com)
81 points by hutteman on June 6, 2012 | 58 comments
29.Netflix begins the deployment of their own content delivery network (zdnet.com)
76 points by fendrak on June 6, 2012 | 43 comments
30.Bookmarklet to see YC / Reddit thread of any URL (see-reaction.appspot.com)
77 points by theone on June 6, 2012 | 22 comments

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: