792: Password Reuse
Title text: It'll be hilarious the first few times this happens.
This comic has three layers: hacking, philosophy, and Google-satire.
It starts off on a practical level, with Black Hat describing a devious social engineering scheme. It relies on the fact that people commonly reuse the same password on multiple websites, and tend to create accounts on new websites somewhat indiscriminately. Thus, one could create a simple Web service to collect users' usernames, email addresses, and passwords. Since many users will reuse this combination on other websites as well, the website owner can try to hack their accounts on other common sites, such as Amazon or PayPal, using the same login info.
In panel 6, the comic suddenly develops a philosophical and ethical bent. Black Hat reveals that he has already carried out step 1, through his numerous unprofitable Web services which he had been running for this very purpose. However, after successfully executing the hack, he realizes that he does not know what to do with all this power. He reveals that he is already financially self-sufficient, and makes a point that money can't buy happiness. He could use his power to realize his sadistic pleasures of messing with people, but he's already a serial asshole. If he had any beliefs or ideology, he could use this power to try to spread them. However, he reveals that "since March of 1997" he doesn't really believe in anything - On March 26, 1997 in San Diego, California, 39 Heaven's Gate cultists committed mass suicide at their compound. The dilemma: Black Hat has cleverly executed a hack that has given him a lot of power, but he doesn't know what to do with it.
The last part of the comic now transitions to a satire on how Google has already gone through both the stages described above. It describes how all of Google's free services are simply a ploy to collect and control all the world's information, similar in concept but grander than the hack described in part 1. It satirizes the notion that behind Google's "Don't be evil" motto is actually an end-goal of using their powers eventually for evil. However, just like Black Hat, once Google reaches the stage where they are able to capitalize on their powers, they find that there is nothing evil left for them to desire. They already make a lot of money, and anything remaining that they wish to do, such as throwing CoD tournaments, isn't evil at all.
This comic was directly referenced in 1286: Encryptic.
- [Cueball at a computer with Black Hat behind him.]
- Black Hat: Password entropy is rarely relevant. The real modern danger is password reuse.
- Cueball: How so?
- Computer: Password too weak.
- Black Hat: Set up a Web service to do something simple, like image hosting or tweet syndication, so a few million people set up free accounts.
- Black Hat: Bam, you've got a few million emails, default usernames, and passwords.
- Black Hat: Tons of people use one password, strong or not, for most accounts.
- [Diagram showing a table of emails, usernames, and passwords.]
- Black Hat: Use the list and some proxies to try automated logins to the 20 or 30 most popular sites, plus banks and PayPal and such.
- Black Hat: You've now got a few hundred thousand real identities on a few dozen services, and nobody suspects a thing.
- Cueball: And then what?
- Black Hat: Well, that's where I got stuck.
- Cueball: You did this?
- Black Hat: Why do you think I hosted so many unprofitable web services?
- Black Hat: I could probably net in a lot of money, one way or another, if I did things carefully. But research shows more money doesn't make people happier, once they make enough to avoid day-to-day financial stress.
- Black Hat: I could mess with people endlessly, but I do that already. I could get a political or religious idea out to most of the world, but since March of 1997 I don't really believe in anything.
- Black Hat: So, here I sit, a puppetmaster who wants nothing from his puppets.
- Black Hat: It's the same problem Google has.
- Cueball: Oh?
- [A meeting at Google headquarters. An executive is talking to some others.]
- Executive 1: Okay, everyone, we control the world's information. Now it's time to turn evil. What's the plan?
- Executive 2: Make boatloads of money?
- Executive 1: We already do!
- Executive 2 (off-panel): Set up a companywide CoD4: Modern Warfare tournament each week?
- Executive 1: That's not evil!
- Executive 2: Ooh, dibs on the lobby TV!
- Executive 1: Okay, we suck at this.