Pages:
Author

Topic: ALL mtgox password has been compromised, change asap, everywhere you used it - page 4. (Read 17598 times)

newbie
Activity: 28
Merit: 0
Man from the future, you seem to know this stuff. How hard would it be for people to bruteforce or crack a reasonably strong password with the encryption in the MtGox file? Say 10 characters alphanumeric.
legendary
Activity: 1806
Merit: 1003
The front page of mtgox is redirecting to something showing this now:

Quote
UPDATE REGARDING LEAKED ACCOUNT INFORMATIONS

We will address this issue too and prevent logins from each users. Leaked information includes username, email and hashed password, which does not allow anyone to get to the actual password, should it be complex enough. If you used a simple password you will not be able to login on Mt.Gox until you change your password to something more secure. If you used the same password on different places, it is recommended to change it as soon as possible.

It also says "One account with a lot of coins was compromised" and "Apart from this no account was compromised, and nothing was lost".  If that's true, how did everyone's password hashes end up on the Internet for public download?  Something fishy is going on.

One have to be an idiot to believe that statement, someone has 500k+ btc just sitting in their mtgox account? lol
full member
Activity: 237
Merit: 100
If this was Facebook I would not like this at all
hero member
Activity: 868
Merit: 1008
I use a customized version of passwordmaker.org ...this let's me hash together one master password with various other details to generate completely unique usernames and passwords for every single online account that I have.  I sleep easy knowing that if my password on one service (like mtgox) has been compromised, that my password (or username) is not compromised on other services.  I highly recommend it (it can be a little inconvenient though).
legendary
Activity: 2940
Merit: 1333
The front page of mtgox is redirecting to something showing this now:

Quote
UPDATE REGARDING LEAKED ACCOUNT INFORMATIONS

We will address this issue too and prevent logins from each users. Leaked information includes username, email and hashed password, which does not allow anyone to get to the actual password, should it be complex enough. If you used a simple password you will not be able to login on Mt.Gox until you change your password to something more secure. If you used the same password on different places, it is recommended to change it as soon as possible.

It also says "One account with a lot of coins was compromised" and "Apart from this no account was compromised, and nothing was lost".  If that's true, how did everyone's password hashes end up on the Internet for public download?  Something fishy is going on.
sr. member
Activity: 371
Merit: 250
I wrote an MMOG backend with better password security than MtGox. Sad
(Two times SHA512 hashes needed to be cracked to find a user's password)
legendary
Activity: 1658
Merit: 1001
I wonder how they were able to get it?

SQL injection?
legendary
Activity: 1806
Merit: 1003
https://rapidshare.com/#!download|359tg2|1969319443|accounts.csv|4023

All mtgox account password has been dumped in their hashed form (can be downloaded from the above link), passwords are being cracked as we speak. Change them asap, anywhere you used it.
Pages:
Jump to: