His password may be ripeadmin, but that admin looked pretty green to me.
RIPE, Regional Internet Registry, hacked because an admin account's password was ripeadmin
Submitted 10 months ago by hal_5700X@lemmy.world to technology@lemmy.world
Comments
yuki2501@lemmy.world 10 months ago
Shadow@lemmy.ca 10 months ago
In a post, the security firm said the username and “ridiculously weak” password were harvested by information-stealing malware that had been installed on an Orange computer since September.
So the password being weak was actually irrelevant here, even if it was 32 random characters they would have pulled it off they pc.
cley_faye@lemmy.world 10 months ago
Depending on the attack vector it could also have pulled it out of other things, but that’s exactly why we have 2FA. And I mean real 2FA, on two different channels, that should be harder to compromise simultaneously.
FartsWithAnAccent@lemmy.world 10 months ago
H A C K E R M A N
AdamEatsAss@lemmy.world 10 months ago
A far more secure password would have been RipeAdmin1$. Gotta get those capitals, lowercases, numbers, and special characters.
moistclump@lemmy.world 10 months ago
Passphrases 14+ characters with upper and lower case, numbers, special characters. Such as r1peAsAm@ang0adm1n!
At least that’s what John Oliver and Ed Snowden say. I trust Ed on this one.
theherk@lemmy.world 10 months ago
Each added character adds much more entropy than character class. Password Strength
billwashere@lemmy.world 10 months ago
It should be
r!p3adm!n
Nurse_Robot@lemmy.world 10 months ago
Where did the P come from?
JaymesRS@literature.cafe 10 months ago
A different language: Réseaux IP Européens
billwashere@lemmy.world 10 months ago
So that’s why they’re call Freedom Fries… mystery explained. 🤣
Chozo@kbin.social 10 months ago
The admin drinks a lot of water.
Aatube@kbin.social 10 months ago
Réseaux IP Européens (European IP Networks)
The article said that RIPE was one of five Regional Internet Registry, not the one. Big HAL fail
Kazumara@feddit.de 10 months ago
Of the two RIPE actually existed first. RIPE isn’t just a forum, it is the community of European and Middle Eastern IP network operators. It started as coordination meetings of some European operators and grew from there. At some point the RIPE community was large enough that they founded the RIPE Network Coordination Center with full time employees as a sort of secretary role for the community. Later when the RIRs were created to decentralize the management of IP resources that job was assigned to the RIPE NCC for the RIPE region.
My work place is one of those original European operators and the colleage who represented us at ripe-1 is also still employed, though close to retirement now :-)
camelbeard@lemmy.world 10 months ago
The p is for password
stardreamer@lemmy.blahaj.zone 10 months ago
according to a detailed writeup of the event by Doug Madory, a BGP expert at security and networking firm Kentik.
What’s a ”BGP expert”? Most of this stuff is covered in an undergraduate networking course. Wouldn’t just “networking expert” do?
autotldr@lemmings.world [bot] 10 months ago
This is the best summary I could come up with:
Orange España, Spain’s second-biggest mobile operator, suffered a major outage on Wednesday after an unknown party obtained a “ridiculously weak” password and used it to access an account for managing the global routing table that controls which networks deliver the company’s Internet traffic, researchers said.
The password came to light after the party, using the moniker Snow, posted an image to social media that showed the orange.es email address associated with the RIPE account.
In a post, the security firm said the username and “ridiculously weak” password were harvested by information-stealing malware that had been installed on an Orange computer since September.
Once logged into Orange’s RIPE account, Snow made changes to the global routing table the mobile operator relies on to specify what backbone providers are authorized to carry its traffic to various parts of the world.
All but one of them also originated with the Orange AS, and once again had no effect on traffic, according to a detailed writeup of the event by Doug Madory, a BGP expert at security and networking firm Kentik.
The creation of the ROA for 149.74.0.0/16 was the first act by Snow to create problems, because the maximum prefix length was set to 16, rendering any smaller routes using the address range invalid
The original article contains 516 words, the summary contains 211 words. Saved 59%. I’m a bot and I’m open source!
macaroni1556@lemmy.ca 10 months ago
,
JaymesRS@literature.cafe 10 months ago
That’s why I only use “hunter2” for mine. With the number, it’s more secure.
laurelraven@lemmy.blahaj.zone 10 months ago
Just looks like a bunch of stars to me
TimeSquirrel@kbin.social 10 months ago
40 years from now when our devices just encode encrypted keys into our brains directly to identify us, we'll still be making this joke.
sawdustprophet@midwest.social 10 months ago
I guess it works because I can’t see the password.
remus989@sh.itjust.works 10 months ago
Nah, you need more numbers in your passwords. That’s why mine is always 123456789!
tigerjerusalem@lemmy.world 10 months ago
That’s it, I’m going to use hunter123456789 now for maximum security!