wethenorth-links.store

what people expect from We The North, and what actually happens

You expect password reuse to be a small risk

WeTheNorth addresses

hn2paw7zadwkcra3qzv5e4q547i7e5lvxm62cfxqftuqdu7moiu2ceyd.onion
hn2paw7zfvndw3dovycegeqmvvnf4pl67b3g2p7pohjlzavloosh73id.onion
hn2paw7zrgujyhnt6mgxlt2q6uhgbke4itpqitxhyfbumq3wtnckbuyd.onion

Printed as supplied, in no order. Nothing here is checked or timed, so an address that opens is not proof of anything. more about the set

#13account and identity

Nobody is targeting me. Reusing a password I remember is a reasonable trade.

what actually happens

Nobody needs to target you. Old breach lists get replayed at scale, and a password you used somewhere else in 2019 is already in one of them.

The gap: you are picturing an attacker who picked you. The attack is a loop over a file.

What the attack actually is

Take a list of usernames and passwords from an old breach. Try each one against a login form. That is it. There is no cleverness and no target selection. The economics work because the list is free and the success rate does not need to be high.

The reason people underestimate it is that they imagine a person deciding to attack them. Nobody decided anything. A machine worked through a file and your line came up.

Why the local situation is worse

On an ordinary site a stuffed login is an inconvenience with a recovery process. Here every part of that process is missing, which turns the same event into a permanent loss.

The username matters too

People reuse handles more than passwords, and a handle is a thread. A name used on a forum in 2016 and again here connects two records that had no business being connected. Search engines remember old profiles for a very long time, and so do archives. Pick a name that has never existed anywhere else and has no personal meaning at all.

What to do

  1. A unique password, generated rather than invented. Human invented passwords cluster around the same patterns.
  2. A unique username with no history. This costs nothing and closes a whole class of linking.
  3. Store both offline, with the signup material from registration, in the same place and the same handwriting.
  4. Turn on whatever second factor the platform offers and store the backup for it the same way.

The objection is always that a long random password is hard to remember. It is, and remembering it is not the job. The job is having it written down somewhere that survives a lost phone, which you already need for the account material anyway.

One detail people get backwards. Changing a password regularly does very little here, because the attack is not somebody slowly guessing yours. Changing it after any hint that a login happened without you is worth doing immediately. Frequency is not the useful variable. Uniqueness is, and it only has to be got right once.

Questions people send about this

Is a password manager safe to use for this?

A local, encrypted, offline one is a reasonable tool. A manager that syncs through an account tied to your name puts a list of your logins under that name.

What if I only reused it on a harmless site?

The harmless site is the one that got breached. That is the whole mechanism.