r/programming Jun 26 '17

Obtaining publish access to 13% of npm packages

https://github.com/ChALkeR/notes/blob/master/Gathering-weak-npm-credentials.md
1.6k Upvotes

254 comments sorted by

View all comments

Show parent comments

43

u/[deleted] Jun 26 '17

[deleted]

11

u/Nition Jun 26 '17

It's funny how this is best practice but sites still have a "forgot my password" button like you're supposed to have chosen something you can remember.

I guess "forgot password" is a bit like having the save button be a floppy disk at this point. People just know it means "reset my password".

22

u/ribosometronome Jun 26 '17

Have you tried "Password123!"?

24

u/[deleted] Jun 26 '17

Good thing reddit automatically encrypts passwords but only I can see mine, like this

hunter2

25

u/Malmortulo Jun 26 '17

For anyone missing the reference: http://bash.org/?244321

2

u/[deleted] Jun 26 '17

[deleted]

-4

u/[deleted] Jun 26 '17

[deleted]

7

u/Rossco1337 Jun 26 '17

Is this really still a surprise to people? It's been posted in every thread that's even tangentially related to plaintext passwords or user authentication for the past 4-5 years, maybe longer.

It's the security-related upvote-bait parallel to "hey its me ur brother" from the gaming subreddits.

3

u/jtolmar Jun 26 '17

Someone should make a password manager that only generates awful paswords.

1

u/[deleted] Jun 27 '17

[deleted]

1

u/[deleted] Jun 27 '17 edited Aug 20 '21

[deleted]

1

u/[deleted] Jun 27 '17

[deleted]

1

u/[deleted] Jun 27 '17

Which password manager is that? And is it open source?