Anyhow, the post got more attention than expected
- People have twitted about it in foreign languages: https://twitter.com/galaxy001/status/945606650714505216
- The popular Nixcraft Facebook page wrote about it: https://www.facebook.com/nixcraft/posts/1932071193472916
- YCombinator wrote about it in their news feed:
https://news.ycombinator.com/item?id=16009459 - The PR itself got more than 300 comments: https://github.com/danielmiessler/SecLists/pull/155/
I would like to explain here how I got to this silly idea. From time to time, I get to consult developers and admins about security. Whenever we talk about passwords I have a few guidelines such as, use 2FA everywhere.I always advise to check if the password is found on any of the lists of SecLists GitHub project. Clearly, if you find your password there it's not a good enough password.
Recently I’ve found myself guiding a SysAdmin that didn’t seem like the brightest tree in the forest. As a security researcher that got me thinking, again, what could go wrong. When I imagined that person might try to solve his problem by attempting to remove the password from the lists, instead of changing it, I thought it’s so hilarious, I must do it.
Apparently, GitHub users liked it too, and got too many comments. Sometimes when I try to load the comments page of the PR I get:
If you appreciate the joke please approve the PR to help me make sure it's the most approved PR on GitHub (https://github.com/danielmiessler/SecLists/pull/155).
Cheers,
Assaf