Episode 3: The Problem with Passwords
TL;DRHigh school students hacked CIA Director John Brennan's AOL email by social-engineering Verizon for his personal info, then using it to pass AOL's security questions. The episode explains how passwords are cracked via brute force,…
We explore how easy it is to turn a jumble of characters into something useful.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: A few months ago, a phone rings on the desk of an operator at Verizon. It's a routine call from one of their technicians in the field. The tech's tools are down, and he needs to confirm that the customer he's meeting with is who they say they are. The technician provides his employee ID, and Verizon gives him the customer's info. It's the basic stuff, the customer's account number, email address, a backup PIN, and the last four digits on his bank card. The call ends. Just a few minutes later, in a different office in a different city, a tech support employee at AOL's email department gets a call from a guy named John Brennan, saying he's been locked out of his email account. AOL needs to verify who he is, so they ask a few security questions, The kind you've probably been asked for in the past. Things like the name and phone number associated with the account and the last four digits on his bank card. Everything checks out and they reset John's password over the phone. Have a nice day. So if you're paying attention, you might have guessed where this is going. That Verizon technician didn't actually work for Verizon. The employee number he provided was fake, and it was all done in an effort to get Brennan's personal info from Verizon so they could then turn around and use it to trick AOL into thinking that they're Brennan. This is called social engineering, and it illustrates one of the many, many problems with passwords. They're only as secure as the people who house them. Social engineering is common. It's a crazy common. So why am I telling you about this one particular instance? Because John Brennan isn't just anybody. He's the director of the CIA. And the people who hacked him, they were high school students. My name is Jordan Blumen.
Speaker 2: And I'm Scott Winder.
Speaker 1: And this is the problem with passwords in this episode of Hacked. Okay. So what is a password? A password is a way of proving that you are who you say you are. You go to a website and you type in your name, you say I'm Jordan, and the website says, okay, prove it. Tell me that thing you told me the other day.
Speaker 2: Right. It's a a level of authentication. You're authenticating who you are.
Speaker 1: Exactly. So if I was trying to pretend to be someone else on that website, where would I start?
Speaker 2: Well, that's a good question. So if you're trying to authenticate as a user and you don't have their password, you have to start looking at how you can can get their password or make up their password. So, you know, one of the oldest forms of attack was something called brute forcing, which was repeated attempts at logging in as somebody using a different password every time.
Speaker 1: You're talking about guessing.
Speaker 2: Yeah. Essentially, mass guessing. But the the real problem with that is is it's just such a big space. So, like, if you consider an eight character password and say there's 60 possible characters, so, you know, you've got uppercase, lowercase, and numbers, that's about 2,600,000,000 guesses you have to have to cover the full state space of how many passwords you could have.
Speaker 1: Isn't that the kind of problem you could just point a computer at, though? You can say guess guess over and over again as fast as you possibly can, powerful little computer.
Speaker 2: Yeah. Yeah. And that's, you know, kind of how it how it was done. But, like, if you think about something like your iPhone or your phone, when you mess up so many login attempts now, they freeze you out. And this is a kind of a protection that's been put in place to stop people from guessing. Right.
Speaker 1: That's kind of where the CAPTCHA came from probably.
Speaker 2: Yeah. CAPTCHA, robots, you know, max number of attempts before they put a time delay in it, things like that. You know, people are very aware of that. That's a very old style of attack, and there's a lot of protection against it now. And it's easy to protect against.
Speaker 1: So if guessing doesn't work anymore, where would a person start?
Speaker 2: Well, people still guess. They just guess differently now. Like, your biggest vulnerability now isn't with somebody randomly guessing your password. You know, that that very infrequently happens. Something that would be much more common is that they get a hold of your password in quotes in the encrypted form after a breach of data from some some website or some service that you use.
Speaker 1: So if they get a hold of my password but it's encrypted, isn't it safe?
Speaker 2: Yes and no. It's safe in the sense that it's being encrypted or it's been hashed. So what that means, you know, is a bunch of brilliant cryptologists came up with essentially a one directional encryption. So something that would that modern computing power can't actually decrypt in any kind of reasonable amount of time. So what they do is they literally take your password or your token of authentication and then hash it. So they run it through this one directional thing, which turns, you know, your little password of six to eight characters typically into, you know, 32 or 64 characters that nobody can really decrypt. So going back to your question about guessing, now what people do is they guess what your password is, encrypt it, and then compare the encrypted version of their guess with the encrypted version of your password to see if they match.
Speaker 1: But wouldn't that still require billions and billions of guesses?
Speaker 2: Yes and no. We go back to your password. We go back to how passwords have evolved. You know, twenty years ago, your password could have been the word password, and 99% of websites and services would have taken it. If you tried to use that as a password today, the site won't take it. They'll tell you that it's too weak. It's not long enough. It's not this. You know, there's everybody's seen these annoying pestering messages when they try to create a password because the system is actively trying to prevent you from having a bad one. But there's an issue because all of these passwords kind of enforce these new rules. You know? There must be an upper case character. There must be a number. There must be one non alphanumeric character, which means, like, a quote space, underscore. But the issue has become that people have started statistically doing the exact same thing, so there's patterns emerging. So when you're told to put an upper case character and you put it in as the first character, when When you're told to add a number, you add it at the very end. So at the end of the day, your password is very similar to what it was. It's just that you followed this pattern of changing it that almost everybody does the exact same thing. And the problem with that is is that it makes the guessing less difficult. All the things that you do that that you think are clever, the hacker at the same time knows that you're doing. So when they look at what your potential password, you know, state space could be, how many potential the 2,600,000,000 guesses, they can pretty much isolate it down and be pretty confident in their guessing by taking, you know, every word in the dictionary and applying a set of rules to it being capitalized in the first ones, adding numbers to the end, or doing something like elite speak conversion, which is another thing that people commonly do, which is replacing o's with zeros, e's with threes, a's with at's, s's with dollar signs. You know, these are common rules that I don't wanna say hackers pretty much invented, but they kinda did.
Speaker 1: So you narrow it down for them by following the same trends and making a password that everybody else follows.
Speaker 2: Right. So I can take a basic word list, you know, let's call it 400,000 words. Run that through a processing algorithm that's adding, capitalizing, adding digits, adding alphanumerics where people would expect, doing lead speed conversions at different levels, so just replacing the o's, just replacing the e's, you know, replacing both the o's and the e's. And I'm generating wordless, you know, in the millions of of password ranges. Let's say I generate 10,000,000 passwords. Those 10,000,000 passwords will be great at guessing people's passwords.
Speaker 1: Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked. So let's walk through like a a hypothetical instance of this. One of these big websites like a a Sony or an Ashley Madison or something has a massive leak. All of their passwords leak out, but they're encrypted. So this giant table of all these encrypted passwords comes out. Where would you start? Where do you find that word list? What does that look like? What does that process play out as?
Speaker 2: Well, it really comes down to what algorithm they hash them in. So, you know, was it m d five? Was it sh a one or SHA one? You know, there's a bunch of different hashing and encryption algorithms, and that's kind of the first place you start. But the beautiful thing is is that most of these algorithms are identifiable. Like, when you see an m d five hash, you'll know it's an m d five hash. It has an exact output set, and you'll know it when you see it if you know what it is. So that's kind of the first thing that you identify is what is encrypting these things. The next question then becomes, is it salted?
Speaker 1: Okay. So what is salting? You probably are asking. So as we said earlier, when you type in your password into a site, what they do is they take that password and they hash it. They run it through a one way only encryption. And the only thing that they keep on file is this jumbled up encrypted version of the password. So, the next time you go to log in to that same site and you type in your password, what they do is they just hash whatever you've typed in, and they compare that against the hash version they have on file. So what salting is, is it's adding another step. With salting, when you make up your password, before the site encrypts it, they add a bunch of stuff to it. It's stuff that only they know. So, hypothetically, they would glue to the end of it 64 random characters that, again, only they know. They've salted it. So why would a website do
Speaker 2: this? So if it's an unsalted password or unsalted hash, I can take any word list, run it against the hashing algorithm, and get the exact same output as your password would be stored in. But if it's been salted, I have to go another step. I have to encrypt my word list with the salt.
Speaker 1: Does that
Speaker 2: make sense?
Speaker 1: I think so. Okay. So so far, we've got company has a leak. All of the users' passwords, hashed and maybe salted, have been leaked out into the world. The hacker who's trying to unencrypt them has figured out how they were hashed. Then what?
Speaker 2: Just to add to the salted thing briefly, and then I'll I'll I'll get to your question. The something like the Ashley Madison leak, the hackers that released that data clearly had, you know, expansive access. They had email accounts. They had server access. They probably had source code access, which would have showed them the salt. So there's ways to get the salt. The salt isn't guaranteed to be protected, but it is a great level of security. And it applies to something else that I'll talk about in a bit called rainbow tables. So you've now got this massive database export of the user table. You know, it's got your name and your username and your password and your email.
Speaker 1: But the password is encrypted.
Speaker 2: But the password has been hashed. What you can do is literally take that password list and brute force it. Run it against wordless. If you've got a dictionary file that you've built or used or made, especially if you know the website's rules for password generation. So when you go to create an account, if it won't let you have a password less than six characters, you know you don't have to test it against passwords less than six characters. I have seen websites that have maximum lengths, which just comes down to laziness in your database configuration often and probably an indicator that they actually save the text version of your password. But you take this massive data list of usernames and passwords, and then you can just essentially barrage it with data.
Speaker 1: Data from this giant word list?
Speaker 2: Yeah.
Speaker 1: So where do you where does one get a giant word list? Is it just a dictionary, or do those words have to be catered to the way people make passwords?
Speaker 2: Yeah. There there's tons of them, and they're publicly available. But then there's, you know, as I previously mentioned, rainbow tables,
Speaker 3: which
Speaker 2: are essentially massive hash specific or password specific or salt specific because they actually make tables that are specific to certain salts that are commonly used by things like Wi Fi access points. Anyway, these massive tables called rainbow tables, which are precomputed hash tables. So instead of it just being a word list and then your, like, brute force attack has to, like, grab a word, hash it, and then compare that hash to the to the password list. These are already hashed. So there's no time needed to hash it, no algorithmic thing. It's literally just doing string to string comparison. They're actually optimized. They use a bunch of algorithms to actually not use as much space and optimize lookup inside of them. So you can test millions and millions and millions of passwords a second.
Speaker 1: If it's testing millions a second, how big a list of potential passwords are we talking about here?
Speaker 2: Like, terabytes. Of just text? Of binary optimized prehashed tables? Yeah. That's a lot. Yeah. But, like, when we're talking terabytes, we're talking every key on your keyboard that could be used in a password to, you know, from password lengths of one to password lengths of, like, nine. But literally, how many passwords in the world does that cover?
Speaker 1: Right.
Speaker 2: Almost all of them? Like, think about all your passwords. Do you have any that are longer than nine characters? Probably not. So then you're vulnerable. That one rainbow table that's ultra high speed, ultra optimized to crack your hashed password. If you were in the Ashley Madison database and they were unsalted passwords, comparing that against, you know, one of those massive tables would probably generate I don't even know. I'm gonna ballpark 75 plus percent of the passwords.
Speaker 1: Which if it's you know, I'm just making up numbers here, but if that original list was, like, 10,000,000 people, who cares if you didn't get the other 25%?
Speaker 2: Yeah. Precisely.
Speaker 1: Okay. So this person sitting there, they've pointed this crazy rainbow table at these hashed passwords, and they get 75 or 60% or 50% back. Got this giant list of emails and passwords. Those are emails and passwords for a site that they know has been hacked. Are they of any real use to them?
Speaker 2: Absolutely. If you've got somebody's email address and their password so let's say jordan@hackpodcast.com was in the Ashley Madison hack.
Speaker 1: We say that email so much, some terrible, terrible noise is gonna happen to it.
Speaker 2: And let's assume that we've cracked your password. What do you think the probability is that that password is the same one you use on your email?
Speaker 1: Probably pretty high.
Speaker 2: A lot of people only use one password or two passwords maybe. And that makes them incredibly vulnerable. Like if just writing some scripts, I could take the output of the Ashley Madison brute force or like my my password cracking on their database and literally trial log in to all of their mail and see which ones I got into. Like, I could automate that if I wanted to. And once you have access to email, it's a whole another world.
Speaker 1: Right. Because as we heard in episode one of hacked podcast, once you have access to someone's email, you can kinda just pretend to be them.
Speaker 2: Your email inbox has taken on a weird form in the Internet today. It's become your key chain. You know, you you carry this thing around in your pocket, and it's got your house key, your car key, your bike lock key. Your email is now that every time you create an account with any service on the Internet, really, the first thing they ask for is an email address. And the primary function of that is password reset. So if I ever get access to anyone's email, especially if it's something that has full text search, in twenty seconds of searching, I know what accounts are associated with that email address, and I can reset their passwords. So once you get access to someone's email, you've got access to all of their accounts that are associated with that email address, which makes email incredibly powerful.
Speaker 1: So the lesson is you should probably have a different password for your email than everything else.
Speaker 2: Absolutely. The way I do it is I have tiers of passwords, and I protect my email at the top of that list. My email passwords are my primaries. They're my most complicated. They're very difficult, and I don't use them anywhere else because I there's no way I want somebody to have my keychain and know my house address. And that's literally what it is when somebody gets access to your email. So I protect those above and beyond anything. And then I I typically have a tier two for social media and other front facing things. You know? Any kind of public presence that might be a little bit more popular, you know, people might see and want access to it. Like, I know a bunch of Twitter accounts over the years have come into, you know, massive hacking engagements like at Matt, and there's a bunch of other examples. So yeah. So the social media ones, I typically, like, keep as a tier two password. And then I have tiers three and four for, you know, things like Reddit and weird esoteric web forums for things that I like and hobbies that I have. So yeah. So I I keep layers of passwords so that if any one site gets compromised or any one thing, I reset the passwords in that layer. Because expecting somebody to have a 100 passwords is, I think, unreasonable. Yep.
Speaker 4: Thinking about refreshing the carpet in your home? Now is the time to do it. For a limited time at The Home Depot, get 10% off installed carpet projects on trusted brands like Lifeproof, Lifeproof with PetProof Technology, Home Decorators Collection, and Traffic Master. Plus, with installation starting at just 49¢ per square foot, upgrading your space is more affordable than ever at The Home Depot. Offer valid 06/11/2026 through 06/28/2026. Exclusions apply for licenses. See homedepot.com/license numbers.
Speaker 1: So where do things like, say, one password services that encrypt and make up a unique password for every site you go on, where do those fit into this whole thing?
Speaker 2: Yeah. I think the the concept behind those is great. But as what was recently shown, you know, actually recently, like, very recently, somebody hacked LastPass. They found exploitations in it. They found holes in it. They found ways, that it was vulnerable. And the problem with that is is that that is actually your key chain, and it's still vulnerable like your email. Because a lot of those systems because they are commercial consumer systems, you know, they're not like key encryption. Like, if you forget your password for your key your your private key and encryption, it's gone. You're not decrypting anything. But things like LastPass and OnePass, these services still require if they get a phone call from, you know, my mother at 11:30 at night saying, I can't log in. They still require the ability to go, it's okay, and help that person out. So so they're they kind of not as tight and secure as other things. So there's still issues with them, but they are kind of a a novel concept. I don't use them, but they are a novel concept.
Speaker 1: Would you recommend them? No comment. Okay. So tiers of passwords, those are good for, you know, saving yourself in the event of, you know, somewhere, some site that you've logged into has a massive leak. But the story at the top of the show, that was social engineering. Someone like John Brennan, that wasn't a guy whose password leaked out somewhere, that was someone who went after him. They went after the holes in the security that you just described, the website that gets the call at 11PM from your mom. How do you protect yourself against those holes in security?
Speaker 3: I don't wanna end the show like we ended the last one and frighten everybody. Scott, do it. So I will say it's really tough because there's a lot of really high profile hacks that have happened in the last, you know, five, ten years that had nothing to do with decrypting people's password. They had nothing to do with, you know, kind of spoofing somebody's email and taking over control of their online life. They had nothing to do with those things. They just have to do with human error somewhere that you've trusted, and that's almost impossible to get away from. And social engineering will certainly be a topic of a future episode because there's some amazing things that can be done and have been done with social engineering. And when I say amazing, I mean amazingly illegal. But there's really no way to protect against human error from people in the chain. Like, we have such basic identity verification systems now. Like, I am pretty sure that I could verification systems now. Like, I am pretty sure that I could figure out your mother's maiden name in less than five minutes. You could figure out mine in probably less than one minute. And that's a common thing. Like, how is that verify who you are? The fact that you know your mother's maiden name. And as long as we keep such low bars to jump over, people will jump over them.
Speaker 1: Do you think that more of these giant, really well publicized hacks are gonna be the thing that forces the people who keep us safe online to raise that bar a little bit?
Speaker 3: Yeah. I think, you know, there's a ton of research going into this, into figuring out ways to create a real password, like a better alternative to the password and a better alternative to verification of identity, you know, and that's a big problem. It's you know, things like Google and a lot of other major systems now have offer something called a, like, a two stage authentication. Even Steam, I think, does it, like the video game provider, where you log in with your password and they'll send you a text message, and then you have to verify from your phone that it's actually you. Or Steam has an app that will pop up a notification saying somebody's attempting to log in from this computer, this IP address, is this you? And if you say yes, it'll log them in. Systems like this have become the kind of the holy grail solution to adding at least one more bar to jump over. They're not a 100% secure, but they're definitely far more secure.
Speaker 1: How long until Facebook takes a blood sample?
Speaker 3: Good question. Good question.
Speaker 1: So we just wanna apologize for the giant delay between episodes two and three. I was on vacation, and then Scott was on vacation, and then I was sick, and then Scott was sick. And now we're both kind of healthy ish.
Speaker 2: Kind of sick ish, as you can tell by the deep rasp in my voice.
Speaker 1: You sound really sultry.
Speaker 2: Thank you.
Speaker 1: Cool. So we just wanted to thank everyone who's still tuning in for being patient with us. We hope to have episode four, you guys, coming up pretty quick.
Speaker 2: Yeah. We're gonna try and get episode four back to back, so next week, hopefully. Episode four's topic is very interesting.
Speaker 1: It's really, really cool.
Speaker 2: I highly recommend you, wait and see.
Speaker 1: Don't forget, you can write us at get@hackedpodcast.com or follow hacked podcast on, you know, the standard social media. Shout out to anyone who wrote us an email. We always really, really appreciate that, and don't forget to subscribe. Otherwise, thank you for listening to another installment of hacked podcast.
Speaker 5: Visible puts the ultimate wireless hack in the palm of your hand. You get unlimited five gs data and hotspot designed to keep you connected. All powered by Verizon's five gs network. Plans start at $25 a month or get the premium Visible Plus Pro plan and save $10 on your first month with promo code hack. Tap the banner to switch today. Terms apply. See visible.com for plan features and network management details.
Speaker 6: You can't reason with the sun. Trust us. We've tried. This summer, it's time to put that angry ball of fire on mute. Columbia's OmniShade technology is engineered to protect you from the sun's harsh rays that can burn and damage your skin. The sun is relentless, but so is our gear. Level up your summer at columbia.com to spend more time outside and less time slathering on aloe lotion. You're welcome. Columbia, engineered for whatever.
Speaker 7: The right window treatments change everything. Your sleep, your privacy, the way every room looks and feels. At blinds.com, we've spent thirty years making it surprisingly simple to get exactly what your home needs. We've covered over 25,000,000 windows and have 50,005 star reviews to prove we deliver. Whether you DIY it or want a pro to handle everything from measure to install, we have you covered. Real design professionals, free samples, zero pressure. Right now, get up to 45% off-site wide, plus get a free professional measure at blinds.com. Rules and restrictions apply.