Skip to content

Oh, very good

Thieves stole jewellery from the Louvre worth €88 million last month. It has now transpired that the two main security systems had the passwords “Louvre” and “Thales”. Thales is the firm that runs one of the systems. And you thought you were remiss in using your dog’s name.

And so what do we think the government will use as the master login – you know, administrator privileges – for the national digital ID system?

0 0 votes
Article Rating
Subscribe
Notify of
guest

22 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Addolff
Addolff
13 days ago

Password1″.

Grikath
Grikath
13 days ago
Reply to  Addolff

Password_01……

Got to have a thingie that’s not a letter or number *and* at least 2 numbers in, and the password must exceed 10 characters, nowadays….

Last edited 13 days ago by Grikath
Jonathan
Jonathan
13 days ago

Starmer’s favourite totalitarian obviously :- JosefStalin#1

Jimmers
Jimmers
13 days ago
Reply to  Jonathan

Alli1 perhaps?

Gurzel Wummudge
Gurzel Wummudge
13 days ago

1984

Norman
Norman
13 days ago

“ID”, obvs. All caps, of course.

dearieme
dearieme
13 days ago

I only use my dog’s name because it’s Kier.

Or, to give him his full title, Sir Cur.

Gamecock
Gamecock
13 days ago

Gamecock broke into a nuclear site computer ~40 years ago.

DEC computers shipped with a standard factory system account and password. I was looking around our network and noticed the presence of the nuke site computer. Just for jollies, I tried to log into the default account. IT WORKED!!! What a bunch of losers. FIRST thing you do when you start up new computer is change the system account password. Better, create new system accounts and just delete the factory account.

Sternly worded letter sent to project manager.

Password “Thales?” Betcha it’s factory default and no one could be bothered to change it. And every Thale system manager in the world knows what the default password is.

Maybe even “Louvre” was delivered system password, and again, no one bothered to change it.

jgh
jgh
13 days ago
Reply to  Gamecock

Every installation process I’ve worked on has included “… delete admin user NOTE irreversable, only do at end of process.” after a setup process creating a cryptic replacement admin user.

Ducky McDuckface
Ducky McDuckface
13 days ago
Reply to  Gamecock

Field / Service?

jgh
jgh
12 days ago

Yes. Things like: new employee, build and provide new laptop; existing employee with dead laptop, build and provide new laptop; XP->Win7 rollout, test PC build and replace where needed; Win7->Win10 rollout, test and replace PC where needed; etc. It all becomes a blur. 😉
Just a rummage though my process scripts, one here near the end says:
Have the Asset number and Serial number ready. Call XXXX… say you need them to change the Local Administrator. Once you log off, the Administrator account will be deleted.
They remoted in and “did stuff” to create a local admin account based on the asset number with a password based on a scramble of the serial number and some internal data.

Chris Miller
Chris Miller
13 days ago
Reply to  Gamecock

It’s not hard to construct a logon script that will try to log onto Internet-facing routers with the password “cisco”. 99.9% of them will have been changed, but that still leaves a lot that haven’t.

Western Bloke
Western Bloke
13 days ago
Reply to  Chris Miller

There was a time when every SQL Server shipped with no password. Microsoft changed the install process so that you had to specify an SA password.

M
M
13 days ago
Reply to  Gamecock

Some operating systems don’t like it when you delete the system account. Just upgraded a Debian install and apparently the default install doesn’t offer to delete “root”.
It’s a single user system (me), so I create a new account which can sudo and disable root.

Western Bloke
Western Bloke
13 days ago

Honestly, government password stuff is better than this. I’ve had to fix things on police systems and the security is insane.

The problem is that really, no-one gives a shit about the Louvre. Yeah, people will say it has priceless art, but all of that art could be 3d scanned and printed and you couldn’t tell it apart from the original without X-rays. Every town could have something that to the human eye is the Mona Lisa. That’s before we get into whether people actually care much about the Mona Lisa rather than going to watch Inception.

Most people only go to show off to their mates that they’re in Paris. You want to see the Mona Lisa? Click on Wikipedia. There I saved you 2 days of travel and £500 in travel. Shit, it probably looks better than it being behind glass, which you have to stand 50′ away from.

Gamecock
Gamecock
13 days ago
Reply to  Western Bloke

But in the Wikipedia version, you can’t tell if she is smiling.

Chris
Chris
13 days ago

Who can forget Kemi Badenoch (for it was she) taking over Harriet Harman’s website in 2008 by guessing Username: Harriet / Password: Harman?

Charles
Charles
13 days ago

According to other reports (e.g. https://www.independent.co.uk/news/world/europe/louvre-security-password-museum-heist-burglary-b2859831.html ) that was the password in 2014 when they had a security audit. Presumably changed as a result of the audit.

But even if it was, is there any suggestion that the thieves exploited this weakness? If not, it’s irrelevant.

johnnybonk
johnnybonk
13 days ago

Passwords giving access to what? Probably nothing serious – file under nothing to see here.

septimusbob
septimusbob
5 hours ago

.

Last edited 5 hours ago by septimusbob
Mission Uncrossable UK
Mission Uncrossable UK
5 hours ago

[

Last edited 5 hours ago by Mission Uncrossable UK
Can you help support The Blog? If you can spare a few pounds you can donate to our fundraising campaign below. All donations are greatly appreciated and go towards our server, security and software costs. 25,000 people per day read our sites and every penny goes towards our fight against for independent journalism. We don't take a wage and do what we do because we enjoy it and hope our readers enjoy it too.
22
0
Would love your thoughts, please comment.x
()
x