Cutout.Pro, an AI-powered visual design platform, leaked 20M records, including email and IP addresses, names and salted MD5 password hashes, which have then been broadly distributed.

https://haveibeenpwned.com/PwnedWebsites#CutoutPro

Haha, brand new company with MD5 password hashes. Maybe they oughta consult about securities with their/other AIs more often. Hopefully, nobody did anything naughty on the site.

Other links on the story:

115 points · 10 comments · view on lemmy.world

10 Comments

ArtVandelay@lemmy.world · 25 pts · 2y (8 replies)

It's a good thing not just everybody can afford a raspberry pi zero that would be necessary to crack an MD5 in seconds

viking@infosec.pub · -1 pts · 2y (7 replies)

That really depends on the password complexity. Sure, you can crack a password of 6-8 characters in below 30 minutes, but anything more complex than that will take days and longer.

My default password is 22 characters long and includes a unique identifier for each service plus a checksum. Say as an example (similar enough to my actual use case) for Adobe I'll have "Ae" (first and last letter of the service) and "41" in a specific position (A = 41 in Hex).

That way even if I repeat the other 18 characters (including symbols, upper and lower case characters) it will take years or even decades on a consumer grade system to crack my password, and the hash is unique for each service/website, so there won't be any collateral damage either, even if some service I used got breached and my password somehow fully exposed.

ReginaPhalange@lemmy.world · 26 pts · 2y (4 replies)

Why do people humble brag about their password strength, but then tell the whole world how to construct rainbow tables designed to crack their passwords?

InnerScientist@lemmy.world · 6 pts · 2y

Iirc rainbow tables are currently useless due to good seasoning salt.

Though password crackers can take a known pattern to drastically increase speed it would still have to do the whole calculation for every password.

viking@infosec.pub · 1 pts · 2y (2 replies)

Like I mentioned, I'm using a related pattern, nothing as simple as the one I sketched out here.

LostXOR@kbin.social · 1 pts · 2y (1 reply)

As long as the other 18 characters are randomly generated that seems secure enough, and a decent way to keep track of which passwords are associated with which accounts.

LordKitsuna@lemmy.world · 9 pts · 2y

Feels like just a roundabout an exceptionally more difficult way to achieve a strong password versus just a password manager. Where you can do ridiculous things like have a 100 character long password

Only to discover that the website will accept 100 characters in the box but actually truncate it to like 40 without telling you

noodlejetski@lemm.ee · 20 pts · 2y

I think I'll stick with a password manager and its randomly generated passwords instead of doing an algebra problem every time I want to check my email

RiQuY@lemm.ee · 5 pts · 2y

I guess then "hunter2" users are in trouble.

user224@lemmy.sdf.org · 10 pts · 2y

Some companies may also just be storing passwords in plaintext.