Poll

What is your main sona?

House Cat
71 (7.7%)
Big Cat
25 (2.7%)
General Dog
24 (2.6%)
Wolf
68 (7.3%)
Fox
92 (9.9%)
Snake
5 (0.5%)
Naga
4 (0.4%)
Lizard
8 (0.9%)
Dragon
55 (5.9%)
Horse
5 (0.5%)
Deer
6 (0.6%)
General Bird
17 (1.8%)
Gryphon
11 (1.2%)
Bat
5 (0.5%)
Otter
10 (1.1%)
Rabbit
7 (0.8%)
Frog
3 (0.3%)
Shark
16 (1.7%)
Whale
7 (0.8%)
Raptor
8 (0.9%)
Owl
8 (0.9%)
Goo Creature
22 (2.4%)
Rubber Creature
3 (0.3%)
Latex Creature
31 (3.3%)
Bear
14 (1.5%)
Weasel
3 (0.3%)
Ferret
10 (1.1%)
Sergal
7 (0.8%)
Camel
12 (1.3%)
DeadFur
18 (1.9%)
Human
352 (38%)

Total Members Voted: 923

Author Topic: Furry Megathread - Furry Things Here  (Read 4484305 times)

figure u guys would find this wolfdog being pet pretty cuuute https://www.youtube.com/watch?v=5OWOQF3dWi0

figure u guys would find this wolfdog being pet pretty cuuute https://www.youtube.com/watch?v=5OWOQF3dWi0
i was happy until i read the description about the wolfs story.

http://bird.school/post/144786857236/urgent-security-notice

If you know what password you used on FA, I'd suggest changing it on any other website you used it as well.
I hardly loving used FA, and now I can't check which one I used because they reset all the passes.
« Last Edit: May 25, 2016, 12:40:23 AM by ShadowsfeaR »

It'll warn you if you try to set it to the one that was compromised.

Edit: Just tested all mine. Thankfully it was the one I don't use anymore.

Edit 2: And of course, the site is broken. If you set it to the 'known compromised password' via your user settings page, neither your previous password nor the one you tried to set it to will work.
« Last Edit: May 24, 2016, 03:05:08 PM by Shift Kitty »

Personally, I'd just leave it un-set and move on to a new website. The fact they store the passwords in unsalted hashes is so incredibly irresponsible.

i was happy until i read the description about the wolfs story.
me too

i cri

Personally, I'd just leave it un-set and move on to a new website. The fact they store the passwords in unsalted hashes is so incredibly irresponsible.
is there a source on the fact that they didn't salt the hashes? I wouldn't necessarily put it past them, but that's a pretty big claim to make without proof :/
also what the heck does "The password hashes, the literal things that decrypt passwords" mean lol

to be 10000% honest i want FA to be sued and to fade
if people cant move on, just kill FA and make them move on.

also what the heck does "The password hashes, the literal things that decrypt passwords" mean lol
I too was going to say this is kinda wonky. Hash algorithms are inherently irreversible, the danger is just if your password is short a computer can try millions of hash combinations until it finds the one matching yours. If you have a password 13 characters or longer and isn't just words or something, it'll take too long to figure it out to be in any real danger unless someone wanted to specifically target you and was willing to put months into it.

Personally, I'd just leave it un-set and move on to a new website. The fact they store the passwords in unsalted hashes is so incredibly irresponsible.
I was only trying to set it because I wanted to know which one I used on it.

I too was going to say this is kinda wonky. Hash algorithms are inherently irreversible, the danger is just if your password is short a computer can try millions of hash combinations until it finds the one matching yours. If you have a password 13 characters or longer and isn't just words or something, it'll take too long to figure it out to be in any real danger unless someone wanted to specifically target you and was willing to put months into it.
They don't really have to specifically target a person. Because they're unsalted, they could just run every password through it and start marking down which ones have matches to which account.
There's a reason hashes are usually salted.

They don't really have to specifically target a person. Because they're unsalted, they could just run every password through it and start marking down which ones have matches to which account.
There's a reason hashes are usually salted.
If they tried to do all the passwords at once that would be a pretty slow process. Sure, you cut out having to do repeat hashing operations, but you'll still have to do 11,000 string comparisons before you can move on to the next hash. At that rate you'll probably only be hitting 5-6 character passwords within the week.

Also salting hashes doesn't do very much in a situation like this. It can help when only a database is breached, since the attackers may not know what the salt is or how it's used. However, in this case the entirety of FA's source code was stolen, so they most likely would have figured out what the salt was anyways if they used one.
« Last Edit: May 24, 2016, 03:50:37 PM by Pecon »

If they tried to do all the passwords at once that would be a pretty slow process. Sure, you cut out having to do repeat hashing operations, but you'll still have to do 11,000 string comparisons before you can move on to the next hash. At that rate you'll probably only be hitting 5-6 character passwords within the week.
Well, not any 5 character passwords. Min is 6. So you'd start right at 6.

Also salting hashes doesn't do very much in a situation like this. It can help when only a database is breached, since the attackers may not know what the salt is or how it's used. However, in this case the entirety of FA's source code was stolen, so they most likely would have figured out what the salt was anyways if they used one.
Fair enough.


God, if it weren't for the jpeg, that pic would be priceless

Personally, I'd just leave it un-set and move on to a new website. The fact they store the passwords in unsalted hashes is so incredibly irresponsible.
They stored it salted and hashed. No need for outrage and if your password was secure before it's still secure now.

http://www.furaffinity.net/journal/7578912/