Difference between revisions of "792: Password Reuse"

Explain xkcd: It's 'cause you're dumb.
Jump to: navigation, search
Line 63: Line 63:
:Executive 1: Okay, we ''suck'' at this.
:Executive 1: Okay, we ''suck'' at this.
{{comic discussion}}
{{comic discussion}}
{{comic discussion}}
[[Category:Comics featuring Cueball]]
[[Category:Comics featuring Cueball]]
[[Category:Comics featuring Black Hat]]
[[Category:Comics featuring Black Hat]]

Revision as of 00:31, 9 March 2013

Password Reuse
It'll be hilarious the first few times this happens.
Title text: It'll be hilarious the first few times this happens.


This comic has three layers: hacking, morals, and Google-bashing.

It starts off on a practical level, with Black Hat describing a devious social engineering scheme. It relies on the fact that people commonly reuse the same password on multiple websites, and tend to create accounts on new websites somewhat indiscriminately. Thus, one could create a simple Web service to collect users' usernames, email addresses, and passwords. Since many users will reuse this combination on other websites as well, the website owner can try to hack their accounts on other common sites, such as Amazon or PayPal, using the same login info.

In panel 6, the comic suddenly develops a philosophical and ethical bent. Black Hat reveals that he has already carried out step 1, through his numerous unprofitable Web services which he had been running for this very purpose. However, after successfully executing the hack, he realizes that he does not know what to do with all this power. He reveals that he is already financially self-sufficient, and makes a point that money can't buy happiness. He could use his power to realize his sadistic pleasures of messing with people, but he's already a serial classhole. If he had any beliefs or ideology, he could use this power to try to spread them. However, he reveals that "since March of 1997" he doesn't really have anything to share. The dilemma: Black Hat has cleverly executed a hack that has given him a lot of power, but he doesn't know what to do with it.

The last part of the comic now transitions to a satire on how Google has already gone through both the stages described above. It describes how all of Google's free services are simply a ploy to collect and control all the world's information, similar in concept but grander than the hack described in part 1. It satirizes the fact that behind Google's "Don't be evil" motto is actually an end-goal of using their powers eventually for evil. However, just like Black Hat, once Google reaches the stage where they are able to capitalize on their powers, they find that there is nothing evil left for them to desire. They already make a lot of money, and anything remaining that they wish to do, such as throwing CoD tournaments, aren't evil at all.

In the conclusion, Black Hat reveals that the only thing he's doing with all his hacked user accounts is to post slightly inaccurate content on Wiki sites.


[Cueball at a computer with Black Hat behind him.]
Black Hat: Password entropy is rarely relevant. The real modern danger is password reuse.
Cueball: How so?
Computer: Password too weak.
Black Hat: Set up a Web service to do something simple, like image hosting or tweet syndication, so a few million people set up free accounts.
Black Hat: Bam, you've got a few million emails, default usernames, and passwords.
Black Hat: Tons of people use one password, strong or not, for most accounts.
[Diagram showing a table of emails, usernames, and passwords.]
Black Hat: Use the list and some proxies to try automated logins to the 20 or 30 most popular sites, plus banks and PayPal and such.
Black Hat: You've now got a few hundred thousand real identities on a few dozen services, and nobody suspects a thing.
Cueball: And then what?
Black Hat: Well, that's where I got stuck.
Cueball: You did this?
Black Hat: Why do you think I hosted so many unprofitable web services?
Black Hat: I could probably net in a lot of money, one way or another, if I did things carefully. But research shows more money doesn't make people happier, once they make enough to avoid day-to-day financial stress.
Black Hat: I could mess with people endlessly, but I do that already. I could get a political or religious idea out to most of the world, but since March of 1997 I don't really believe in anything.
Black Hat: So, here I sit, a puppetmaster who wants nothing from his puppets.
Black Hat: It's the same problem Google has.
Cueball: Oh?
[A meeting at Google headquarters. An executive is talking to some others.]
Executive 1: Okay, everyone, we control the world's information. Now it's time to turn evil. What's the plan?
Executive 2: Make boatloads of money?
Executive 1: We already do!
Executive 2 (off-panel): Set up a companywide CoD4: Modern Warfare tournament each week?
Executive 1: That's not evil!
Executive 2: Ooh, dibs on the lobby TV!
Executive 1: Okay, we suck at this.

comment.png add a comment! ⋅ comment.png add a topic (use sparingly)! ⋅ Icons-mini-action refresh blue.gif refresh comments!


And now it turns out that Google gives our data to NSA....sigh. 07:58, 11 June 2013 (UTC)Monica

What happened in March of 1997? MR (talk) 18:23, 4 April 2013 (UTC)MR

Hi! After consulting Wikipedia's article about March 1997 (http://en.wikipedia.org/wiki/1997), I think there are two main incidents Black Hat could refer to:

  • The Phoenix Lights, a group of supposed UFOs, turned out to be probably military aircrafts.
  • The mass suicide committed by 39 Heaven's Gate cultists.

Since we know little about Black Hat's life in 1997, we could argue that he was expecting an extra-terrestrial contact or that he was attracted by the ideas of that creed - and that the disillusion brought him his present disbelief in things. Of course those are just hypotheses, and don't seem to fit the character as we know him...Inverno1407 (talk) 11:30, 15 April 2013 (UTC)

I honestly believe that he created the Heaven's Gate cult and he views their mass suicide as his crowning achievement in getting people to believe things, it just isn't getting any better than that, so he doesn't believe in anything anymore. 13:03, 30 October 2015 (UTC)

"In the conclusion, Black Hat reveals that the only thing he's doing with all his hacked user accounts is to post slightly inaccurate content on Wiki sites."

This paragraph has been present since this explanation was added. I can't see how it is arrived at from the comic. (So I wonder who User: might have been...) Mark Hurd (talk) 14:10, 15 April 2013 (UTC)

I removed some slightly inaccurate content from this wiki. It was the bit about Black Hat posting slightly inaccurate content on wiki sites. 00:33, 15 May 2013 (UTC)

Does anyone know if he had anything to do with the article on "taking the piss"?

I used Google News BEFORE it was clickbait (talk) 16:10, 26 January 2015 (UTC)

How does this compare in light of 792:Password Reuse? Saibot84 (talk) 05:06, 6 June 2013 (UTC)

The "March 1997" issue is still a mystery to me. May be a global computer virus attack? I will go through all days on wikipedia. The month summery presents not the solution.--Dgbrt (talk) 17:27, 6 June 2013 (UTC)

Conisdering how blackhat loves messing with people, I seriously doubt anything at all hapened in March 1997. He's just messing with us! 02:43, 7 July 2013 (UTC)

Oooo, I dunno. Given Black Hat's odd tastes, *anything* from March 1997 could have caused him to lose his faith: Paul McCartney being knighted, Tom Cruise winning an Oscar, the U.S. Supreme Court hearing arguments on Internet Indecency, India's Ministry of Charity choosing a successor to Mother Theresa, Gene Roddenberry's ashes going into orbit, the Brazil Senate finally allowing women members to wear slacks... Anything!! [[1]]

Wow, look at this historical CNN page: http://edition.cnn.com/ALLPOLITICS/1997/03/19/scotus.cda/. The Communications Decency Act is the most likely item from your list.--Dgbrt (talk) 08:21, 2 August 2013 (UTC)
39 Heaven's Gate cultists committed mass suicide
If he was upset at causing their deaths or having accomplished their deaths, has little to prove now nor reason to repeat the act, he is on pause; we wait.
I used Google News BEFORE it was clickbait (talk) 16:10, 26 January 2015 (UTC)

My opinion is that Black Hat referred to Bill Clinton banning federal funding for research on human cloning in March 1997. (talk) (please sign your comments with ~~~~)

How would that create an hiatus in Back Hat's career?

I used Google News BEFORE it was clickbait (talk) 16:10, 26 January 2015 (UTC)

Hey! I though I'd throw in the opinion that perhaps March 1997 was a month of personal importance to Black Hat rather than anything societal. If the 1997 coincides with any of those standard "loss of idealism and innocence years" for Black Hat, then I'd say that's pretty likely what Randall was going for. (talk) (please sign your comments with ~~~~)

Hi - the last line about the TV show DIBS is wrong. DIBS came out in 2014 - the comic in 2010. What the last panel is referring to is calling dibs on the TV to play CoD4. (talk) (please sign your comments with ~~~~)

Google's "don't be evil" is no more

Google removed that "don't be evil" thing from their motto...

  • password change intensifies* 06:35, 5 July 2019 (UTC)

TV Tropes links to this comic as an example of one of the strips that have aged the worst. LendriMujina (talk) 19:16, 28 January 2022 (UTC)

As of 2022 as I write, Google has now set itself up to be the password manager for random non-Google web sites, so they have many peoples' credentials. Of course, Microsoft followed their usual practice and did the same thing, but not quite as seamlessly. Nitpicking (talk) 11:55, 8 May 2022 (UTC)