# I Just Logged In As You: How It Happened

**URL:** <https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181>\
**Category:** blog\
**Created:** [May 5, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181 "2009-05-05T00:00:00Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![codinghorror](https://discourse-cdn.codinghorror.com/user_avatar/discourse.codinghorror.com/codinghorror/32/36371_2.png) [@codinghorror](https://discourse.codinghorror.com/u/codinghorror)\
**Post date:** [May 5, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/1 "2009-05-05T00:00:00Z")

</div>

In my previous post [I Just Logged In As You](http://www.codinghorror.com/blog/archives/001262.html), I disclosed that someone was logging in as me -- specifically because they **discovered my password**. But how?

* * *
This is a companion discussion topic for the original blog entry at: [http://www.codinghorror.com/blog/2009/05/i-just-logged-in-as-you-how-it-happened.html](http://www.codinghorror.com/blog/2009/05/i-just-logged-in-as-you-how-it-happened.html)

---

<div class="post-metadata">

**Author:** ![ian6](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/i/e9bcb4/32.png) [@ian6](https://discourse.codinghorror.com/u/ian6)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/2 "2009-05-06T00:00:00Z")

</div>

Ok, I think i’ve finally heard enough, and tried it enough to agree that openid is the right thing to do.

---

<div class="post-metadata">

**Author:** ![Sal](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/s/58f4c7/32.png) [@Sal](https://discourse.codinghorror.com/u/Sal)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/3 "2009-05-06T00:00:00Z")

</div>

Knowing the salt and having the hash lets you do a dictionary attack on your own machine(s), so you don’t need to use a MD5 database.

Trying to maintain unique passwords for each and every site is a real pain. Even the best methods are dependent on a master password, which comes with its own problems, not the least of which is that you can lock yourself out of everything.

The faster some kind of biometric scanner comes equipped by default on every network-capable device, the better.

---

<div class="post-metadata">

**Author:** ![Paolo](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/p/6f9a4e/32.png) [@Paolo](https://discourse.codinghorror.com/u/Paolo)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/4 "2009-05-06T00:00:00Z")

</div>

I am going to go ahead and guess your password was: wumpus

---

<div class="post-metadata">

**Author:** ![Jonas](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/j/aeb1de/32.png) [@Jonas](https://discourse.codinghorror.com/u/Jonas)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/5 "2009-05-06T00:00:00Z")

</div>

Could someone please explain to be – simply but very exactly – how a salted password would help?

From what I know, you store the salt in plaintext(-equivalent) form to concatenate the password with in order to protect against rainbow table attacks. A dictionary attack against a single password, which this was, is not harder with a salted password.

---

<div class="post-metadata">

**Author:** ![Suroot](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/s/858c86/32.png) [@Suroot](https://discourse.codinghorror.com/u/Suroot)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/6 "2009-05-06T00:00:00Z")

</div>

I cannot stand people who say Hahaha I hacked you because your password is too weak which by the way has never happened. In my opinion it’s the laziest hacking I can imagine; using rainbow tables? Even lazier. Come on, get real, come up with a new exploit or something that allowed you to find the password.

But what makes me even more bleh is the actual guy in this case: oh you signed up with a password on a site I used to work for. HAHA, that’s probably the most unethical thing I’ve ever heard of, calling yourself ethical is anything but… That is called phishing, plain and simple; go look it up. It’s so sad though, I’m so sad that people don’t even try to find new exploits and just use a client side phishing attack or some stupid thing like that.

Anyway, have fun with your hopes of being someone who matters. Clearly the only thing you’ve done is hoped that Jeff would hire you in security; my advice, don’t bother you can find this kind of experience in any 2-bit network security firm.

---

<div class="post-metadata">

**Author:** ![codinghorror](https://discourse-cdn.codinghorror.com/user_avatar/discourse.codinghorror.com/codinghorror/32/36371_2.png) [@codinghorror](https://discourse.codinghorror.com/u/codinghorror)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/7 "2009-05-06T00:00:00Z")

</div>

If my OpenID password gets owned, then I’m owned on several sites.

> [@Steve\_W](#):
>
> How is that any different than your email password getting owned? Then you’re owned on EVERY site, courtesy of reset my password via email links

1. Generate the MD5sum of your password (e.g. [http://www.md5generator.com/](http://www.md5generator.com/) )
2. Google it

Yep, excellent advice.

How is an idiot supposed to work out which are the secure providers?

See above email comment. You use email, yes? Better hope they do passwords right!

most of the internet backed up 37 Signals when it came out they weren’t storing salts with their passwords.

Ooh, that’s really bad. I hadn’t seen that.

[http://www.jgc.org/blog/2009/05/can-you-trust-37signals-with-your.html](http://www.jgc.org/blog/2009/05/can-you-trust-37signals-with-your.html)

---

<div class="post-metadata">

**Author:** ![empraptor](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/e/eb9ed0/32.png) [@empraptor](https://discourse.codinghorror.com/u/empraptor)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/8 "2009-05-06T00:00:00Z")

</div>

this is nothing. i once signed up for an online dating site my friend recommended.

it was piece of crap. design painful to the eye. horrible user interaction.

but something happened the next day that scared the shit out of me. I GOT MY PASSWORD EMAILED TO ME.

i deleted my account the next day. but i have a feeling that the password i used for social networking websites and news aggregation sites is still on their machine, waiting for someone to harvest it along with password of all the other users.

---

<div class="post-metadata">

**Author:** ![Steve\_W](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/s/ba9def/32.png) [@Steve\_W](https://discourse.codinghorror.com/u/Steve_W)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/9 "2009-05-06T00:00:00Z")

</div>

How is that any different than your email password getting owned? Then you’re owned on EVERY site, courtesy of reset my password via email links

Indeed, providing the hacker knows EVERY site you visit. Do OpenID providers not allow you to rest passwords via email?

---

<div class="post-metadata">

**Author:** ![empraptor](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/e/eb9ed0/32.png) [@empraptor](https://discourse.codinghorror.com/u/empraptor)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/10 "2009-05-06T00:00:00Z")

</div>

i should mention too that passwords are apparently emailed to users of that dating site on a regular basis, maybe everyday.

i tried to email the guy who developed/maintain the site. didn’t hear from him.

---

<div class="post-metadata">

**Author:** ![Seth24](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/s/e56c9b/32.png) [@Seth24](https://discourse.codinghorror.com/u/Seth24)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/11 "2009-05-06T00:00:00Z")

</div>

Erm… one prolonged and interwoven set of weak moments, than.

Since we are all frank and honest on the subject of broken security here… when will these oranges be uprooted and cease being pine-apples in disguise?

This orange thing has been more than the required moment of weakness now. And in case anyone (Jeff?) still wanted to retort: Well I don’t see any spam I’d like to repeat: this site is _for the users_ not _against the spammers_.

Right now, the real users are paying the cost to provide _no protection_ against the _absent_ spammers.

* * *

I forgot to enter the correct word again. Maybe the word is not correct anymore?

---

<div class="post-metadata">

**Author:** ![dude](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/d/f19dbf/32.png) [@dude](https://discourse.codinghorror.com/u/dude)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/12 "2009-05-06T00:00:00Z")

</div>

@Matt (and WhaleDawg)

I do something similar to what Whaledawg does.

Google mail = gmailyaba6319  
Yahoo = yahooyaba6319  
Stack Overflow = soyaba6319

It isn’t perfect but it is a heck of a lot better than using the  
same password everywhere.

orly? If I admin’d gmail and saw that your password was gmailyaba6319 and that you also had a yahoo email address, I know which password I would be trying first.

@WhaleDawg

While your version may be slightly more obfuscated, applying any pattern to your passwords is weakening them. And since you admit to using KeePass and rarely entering them by hand, you could just as easily be using something random and strong.

---

<div class="post-metadata">

**Author:** ![codinghorror](https://discourse-cdn.codinghorror.com/user_avatar/discourse.codinghorror.com/codinghorror/32/36371_2.png) [@codinghorror](https://discourse.codinghorror.com/u/codinghorror)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/13 "2009-05-06T00:00:00Z")

</div>

Oh, and for those who claim my password was a dictionary word, and thus this is a de-facto dictionary attack. Well, I just went to

[http://www.merriam-webster.com/dictionary/](http://www.merriam-webster.com/dictionary/)

… and entered my old password there:

The word you’ve entered isn’t in the dictionary. Click on a spelling suggestion below or try again using the search bar above.

Like I said, it _ain’t a dictionary word!_ It might be in cracking tables somewhere, but it isn’t a dictionary word, at least not of the type you can use in Scrabble without getting challenged…

---

<div class="post-metadata">

**Author:** ![Doug\_T](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/d/58956e/32.png) [@Doug\_T](https://discourse.codinghorror.com/u/Doug_T)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/14 "2009-05-06T00:00:00Z")

</div>

Is it worth revealing the open id provider?

---

<div class="post-metadata">

**Author:** ![Billt](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/b/ecc23a/32.png) [@Billt](https://discourse.codinghorror.com/u/Billt)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/15 "2009-05-06T00:00:00Z")

</div>

Will this user come forward to claim the Stack Overflow Hacker badge? I don’t see any wrongdoing against SO or you, since they were nice enough to point out the vulnerability and demonstrate it. You also got two good blog posts out of it. I could imagine the owner of the other site (the one the hacker helps out at, that doesn’t salt their passwords) might be a little upset if (when?) word gets out that they were hacked by a trusted volunteer, but it sounds like they were warned about using salt awhile back.

---

<div class="post-metadata">

**Author:** ![Saj](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/s/9de0a6/32.png) [@Saj](https://discourse.codinghorror.com/u/Saj)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/16 "2009-05-06T00:00:00Z")

</div>

This was a good read!

---

<div class="post-metadata">

**Author:** ![luboa](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/l/cab0a1/32.png) [@luboa](https://discourse.codinghorror.com/u/luboa)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/17 "2009-05-06T00:00:00Z")

</div>

you should award hacker badge now… because next time next person might not rather tell you 🙂

---

<div class="post-metadata">

**Author:** ![Neil\_Naidoo](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/n/e95f7d/32.png) [@Neil\_Naidoo](https://discourse.codinghorror.com/u/Neil_Naidoo)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/18 "2009-05-06T00:00:00Z")

</div>

jeez Jeff arent you a bit afraid now, its official, you have a stalker.

---

<div class="post-metadata">

**Author:** ![JamesR](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/j/a9a28c/32.png) [@JamesR](https://discourse.codinghorror.com/u/JamesR)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/19 "2009-05-06T00:00:00Z")

</div>

Is using OpenID, or Windows Cardspace for another example, beyond most users tolerance or attention span? How can we get easier?

---

<div class="post-metadata">

**Author:** ![John\_W](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/j/50afbb/32.png) [@John\_W](https://discourse.codinghorror.com/u/John_W)\
**Post date:** [May 6, 2009, 12:00am UTC](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181/20 "2009-05-06T00:00:00Z")

</div>

I always salt AND pepper my passwords. 😛

[Next page](https://discourse.codinghorror.com/t/i-just-logged-in-as-you-how-it-happened/181.md?page=2)
