Slashdot Mirror


Bad Password Allowed Swedish Watergate

fredr1k writes "The Swedish Watergate reported earlier this week was possible because of the usage of terrible weak passwords (Swedish) and a not functional IT policy. The Swedish newspaper Göterborgs-Posten reports the source of the password was a partymember who's account was "sigge" with password "sigge" and was "stolen" in march this year. Seasoned Slashdot readers would call it "a-not-so-hard-to-crack-password". "

36 of 248 comments (clear)

  1. Hmmm... by BrokenHalo · · Score: 3, Funny

    Seasoned Slashdot readers would call it "a-not-so-hard-to-crack-password".

    I would have thought a snotty-nosed 11-year-old would regard that password as not-so-hard-to-crack. Oh well, nothing to see here, move on please...

    1. Re:Hmmm... by carpeweb · · Score: 5, Funny

      Seasoned Slashdot readers
      vs.
      snotty-nosed 11-year-old

      So, why was this not modded redundant??

      Aw, c'mon folks, let's laugh at ourselves once in a while ...

    2. Re:Hmmm... by Rob+T+Firefly · · Score: 5, Funny

      That rattling sound you hear is everyone on Slashdot changing their passwords at once.

    3. Re:Hmmm... by beef3k · · Score: 5, Funny

      "kinda strong" eh? That should be easibly crackable with a simple dictionary attack.

    4. Re:Hmmm... by Fordiman · · Score: 3, Funny

      don't think so. It's based on the Phonic64 transform with numbers and punctuation at >10 characters.

      --
      110100 1101000 1101000 1100110 0 1101111 1101000 1100011 1
    5. Re:Hmmm... by CommunistHamster · · Score: 3, Funny

      Let's see now...Username: "Fordiman", Password: "kinda strong" Success!

    6. Re:Hmmm... by kalirion · · Score: 5, Funny

      Pffft, nobody can guess my password, 'hunter2'. I know you only see '*******' there, but I actually typed in my real password. This is one feature I'm really glad Slashdot stole from IRC.

  2. Incredible! by Guaranteed · · Score: 5, Funny

    I've got the same password on my briefcase!

  3. Effective PW by oahazmatt · · Score: 5, Funny

    Let's not forget the user who actually had a decent password.

    uid: schef
    pwd: mmborkburdyhurdymurdy

    --
    Those who believe the Internet is private,
    find their privates are on the Internet.
  4. Many theories about leaked passwords by pipatron · · Score: 5, Informative

    There are atleast three ways this password could have been found. a) My brother lives in the town where these passwords were leaked, and he said that their office use unencrypted WLAN. b) The guy who presumably leaked it is in the office right next to the guy called 'Sigge'. c) As the article thinks: The password was very easy to crack. The latest rumour is that the guy who leaked the password (the left party) had a homosexual affair with the guy who *used* the password (the right party).

    --
    c++; /* this makes c bigger but returns the old value */
  5. Password by Frankie70 · · Score: 3, Funny

    The Swedish newspaper Göterborgs-Posten reports the source of the password was a partymember who's account was "sigge" with password "sigge"

    My next password is going to be Göterborgs-Posten.
    Try cracking that.

    1. Re:Password by grazzy · · Score: 5, Funny

      Since they spelled Göteborg wrong, yeah, it'll be a damn good password.

  6. Honestly unsurprising by mendaliv · · Score: 5, Insightful

    They're politicians, not security experts. I hear about this sort of problem all the time... in my own workplace, we talk about the people on the 3rd floor with their one-character passwords and machines that are hacked into on a daily basis.

    In the end of course, the system administrator is going to catch heat for not having a strong password policy. Even though he/she would've caught hell if there had been one implemented in the first place.

    1. Re:Honestly unsurprising by hdw · · Score: 3, Informative

      Well the it admin/manager _should_ catch heat for it.

      We're not talking about some small 3 person company here. We're talking a (by swedish standards) large and established political party organisation.

      If I was made responsible for running that net/service I'd ask for a security policy established by management and make sure that we followed up on it's use.

      The damage that can be inflicted on an organisation like this by one single idiot with access to that net is massive.

      If the admin is the only tech savvy enough to understand those issues then it's his or hers frikken obligation to take that issue up with management and explain what could happen.

      But should also note in this issue that gaining unathorized access to a private network is illegal, no matter how this access was achieved.

      It should be quite obvious to any of the people involved that accessing data from a rival party's internal network is a criminal offence. // hdw

      --
      Executive Pope (small) Kallisti Engineering
    2. Re:Honestly unsurprising by hazem · · Score: 5, Insightful

      In the end of course, the system administrator is going to catch heat for not having a strong password policy. Even though he/she would've caught hell if there had been one implemented in the first place.

      This is where the sysadmin has to figure out how to make a convincing argument that the suits will understand. If he thinks a strong password policy is important, that is.

      Suits aren't security experts, and they don't need to be. In fact, they're not necessarily experts in everything/anything. That's where the sysadmin needs to learn the same skills that everyone else uses to influence them. Make a case, with pros and cons, costs and benefits and make a proposal. It doesn't have to be extensive. I just has to have the information needed to make a decision.

      Then, let them make the decision. If they say "yes", then you have their backing when enforcing an unpopular policy - and they're already in the know when people complain. If they say "no"... well, you've covered your backside, or if you really believe it in, you need to make a more convincing case.

      It's not black magic... but so many IT folks are either unable or unwilling to talk to non-IT decision-makers in a way that gets them to make favorable decisions. It's an important skill.

  7. End user password selection by trazom28 · · Score: 4, Informative

    This is all too common in many places. One company I worked for, about.. 1/3 to 1/2 of the users used some form of their name, and a number incrementation. I freaked out one who was *-18 asking him.. "so, you've been here a year and a half?" He had no idea how I did the math on that one.

    Eventually, we put in place a very, very restrictive password policy. No incrementing numbers, no password similar to last month's password, etc. You wouldn't believe the riots in the streets. But, we held firm, and eventually, the noise died down, and everyone finally is using more secure passwords.

    --
    {} ------ When I think of a good sig, I'll put it here
    1. Re:End user password selection by Zadaz · · Score: 5, Insightful

      And I'm sure a vast increase on post-it notes with cryptic characters stuck on monitors and backs of keyboards.

    2. Re:End user password selection by tygerstripes · · Score: 5, Interesting
      Can't remember where I read it (prolly /.), but there was an article that gave a very convincing argument to the effect that changing your password every month is totally without benefit. It's a common-rule-of-thumb kind of practice that has been handed down from admin to admin for years, probaby from early Unix days, and doesn't have any useful purpose anymore.

      Incremental-number passwords are an inevitable side-effect of this sort of policy and, even where password policy is more carefully implemented, the fact that average-joe users have to change it monthly anyway is a chore that WILL lead to short-cuts and, ultimately, weak passwords (or rather, associative passwords that are easy to infer after a little observation).

      Try just having a very strict policy on passwords, and scrapping the regular-change part of it. People can be imaginative and obscure once, but ask them to do it regularly and they get sloppy.

      --
      Meta will eat itself
    3. Re:End user password selection by Score+Whore · · Score: 4, Insightful

      I worked as a contractor for the Air Force for a while. They had a real strong policy in place on the Windows domain with the appropriate DLLs that would disallow "weak" passwords. Weak passwords being anything less than six letters; must have three of: upper case, lower case, numbers, symbols; must be substantially different than previous passwords; must not include words in it. Except that their dictionary includes two and three letter words. So you could have a password such as '1xIf%at$3' and it would be invalid since it has two two-letter words 'if' and 'at'. When deciding to implement draconian enforcement of your policies make sure your enforcement processes aren't stupid.

    4. Re:End user password selection by hswerdfe · · Score: 3, Interesting

      ahh, yes More Secure.
      one system I log into at work requires "strong passwords"
      ie
        * has to be very diffrent from your last 10 passwords
        * has to have special chars
        * has to change your password every 2 months.

      the problem is I login to this system every 6 weeks.
      so every! time need to login I
        1. Call the IT desk
        2. Ask them to reset my password
        3. They Email me my password.
        4. I login

      When the password is reset there is no Idenification of me.
      They simply assume that access to my work email is valid enough

      By Increasing the level of security They have effectivly reduced the level of security to that of a seperate system (company email).

      BTW: company email pollicy is change every 6 months, incrimenal is allowed.

      Question:
      How many requests of Password resets do you get with your system?
      What method of Password distribution do you use?
      What method of verification do you use on reseting a password?

      --
      --meh--
  8. Other passwords of note. by Tackhead · · Score: 5, Funny
    President Scroob: 12345
    President Nixon: iam!acrook
    President Clinton I: hopemyhusbanddoesntfindoutaboutthepassword
    President Bush I: anybodybutmysons
    President Clinton II: wishmyhusbandtoldmemonicawasbi8yearsago
    President Bush II: 12345
    President Quayle I: potatoe

    Don't blame me for that last one. My password was "colbertstewart2012".

  9. Password? by madshot · · Score: 5, Interesting

    Here is the real question.. Is it a USER problem or an ADMINISTRATOR problem. Sounds like they need to hire a new IT director with a since of security. If that IT director allows passwords like that he probably also is running a firewall hosted in a Windows XP Pro machine and ICS and no service packs or hot fixes. All of the internal IP addresses are 192.168.x.x because of ICS so I'm sure the server is .1. Heck, the director might have even turned on Remote Desktop Administration on the box so he could manage it from home without a VPN and the administrator accounts password on that box is either blank, password, or god. Well, best of luck to their director or whomever is in charge of their computer network.

    --
    Obama = Socialism.
  10. Seriously by Psionicist · · Score: 5, Informative

    This is non-news. What happened was a member of the Social Democrats youth section _gave_ a username and password to a former member in the Liberal Party (which are not liberal at all BTW) youth section, around 2005! Of course, as the Social Democrats are about to lose the election (september 17th) they use this "news" to spread some primitive form of political FUD about the opposition.

  11. Keyboard Patterning - at least it makes them think by w33t · · Score: 4, Interesting

    You know, in my department we've found that a great way to introduce users to more complicated passwords is to introduce them as keyboard pattern passwords.

    Of course we have complexity requirements, but it's amazing how a user can find a way to simplify a complexity requirement. Think a user unknowledgeable, but never think a user unclever - I always say...well, actually that's the first time I've said that...back to my point.

    While these patterned passwords may not be as hard to crack as truly random passwords, they are at least non-semantic.

    for example 1al02sk93dj8 - I imagine this password is probably pretty common, but if it were scrawled on a stickynote on someones monitor it would discourage causual account browsing by a coworker.

    Does anyone know if brute-force methods take into account keyboard patterning?

    by the way 1al02sk93dj8 is not my accounts password - so don't even think about trying it! ;)

  12. password tips by digitalderbs · · Score: 5, Funny

    This is a good opportunity to outline a few tips for strong passwords. For example, I use my username twice and the number of states as my password.

    1. Re:password tips by digitalderbs · · Score: 5, Funny

      I, digitalderbs, Is a COMPL3TE iDiOT AND MorON!1!!111 OMG.

      I also have small reproductive organs!11!

  13. Swedish passwords by MadFarmAnimalz · · Score: 5, Funny

    Yes, Swedish passwords are weak. We Danes have known this for many years; it is inevitable given that the average number of syllables per word in Swedish is 1.22 (scientific studies have shown it!).

    "sigge", a duosyllabic password, is an indication that the user was a member of the upper strata of Swedish society, with Abba and Ace of Base.

    (NB: I can handle pissed off Swedes, but not moderators lacking the humor gene)

    --
    Blearf. Blearf, I say.
  14. Not only bad password. by Lussarn · · Score: 3, Informative

    From what I understand (having trouble understanding the laymensterms of daily tabloids) it was also a completely open wifi network.

  15. A little joke by SlashGet · · Score: 5, Funny

    - What's the opposite to firewall? - Watergate

  16. Re:Stig-Olof "Sigge" Fribergs by JackBuckley · · Score: 4, Funny

    From TFA: Själv tycker han inte att han handskats ovarsamt med sina inloggningsuppgifter. Translation: My hovercraft is full of eels!

  17. Re:Keyboard Patterning - at least it makes them th by SatanicPuppy · · Score: 4, Interesting

    Anyone else use the post-it-on-the-monitor as a booby trap? If anyone uses the post-it password on my monitor it sets off a series of security cascades that culminates with me getting a picture of them on my phone.

    One day I hope to catch someone other than a janitor trying to surf porn. =P

    --
    ad logicam Claiming a proposition is false because it was presented as the conclusion of a fallacious argument.
  18. choosing good passwords by rice_burners_suck · · Score: 3, Funny

    mine is 12345. Nobody would ever guess that one. It's a password only an idiot would put on his luggage.

  19. All Your Swedes by Kamiza+Ikioi · · Score: 4, Funny
    Captain: Take off every 'sigge' !!
    Captain: You know what you doing.
    Captain: Move 'sigge'.
    Captain: For great justice.


    Seasoned Slashdot readers would call it "a-not-so-hard-to-crack-password"


    Seasoned Slashdot readers probably use zig:zig on BugMeNot and other "social" logins. I guess it just translates different in Sweden, kinda cute even... mental images of the Swedish Chef singing AYB.
    --
    I8-D
  20. Bait by miffo.swe · · Score: 3, Interesting

    Many of us swedes thinks this was a planned event where the login was "leaked" to the opposition by purpouse. The swedish social democrats would probably stop at nothing to keep in power. The person who did the breakin (Per Jodenius) was a former Social Democrat. This person is from the same town (Växjö) and local Social Democrat Youth member in the same circuit as the journalist ( Fredrik Sjöshult )who blowed the whistle. The fact that this happened just hours after the leading party (from the polls) had his turn in the national TV is to much for it to be a coincidense.

    Ugly indee and not very democratic.

    Its like, if you hassled a country for not being democratic and then imposed sanctions on them for choosing the wrong people in the votings....oh, wait..

    --
    HTTP/1.1 400
  21. Re:Spaceballs: The Movie by fbjon · · Score: 3, Funny

    My suitcase goes to 11.

    --
    True confidence comes not from realising you are as good as your peers, but that your peers are as bad as you are.
  22. Re:Informative?? by miceliux · · Score: 3, Funny

    but I'm first!!!!