thewayne: (Default)
[personal profile] thewayne
McD's hired a company called Paradox.AI to run an "AI" chatbot to conduct hiring interviews for its restaurants. Pretty basic stuff. I'm a little unclear as to how much of the application/interview/hiring process Paradox was responsible for, but it at least conducted an online interview with the applicants.

There was a recent data spill from Paradox that exposed "64 million records, including applicants’ names, email addresses and phone numbers." That's a lot of records. Then again, McDonald's has a lot of locations and high turnover.

Security researchers were able to get in to McDonald's access portal by guessing their password. Said password?

1
2
3
4
5
6.

I guess I'd better change the combination on my luggage.

https://krebsonsecurity.com/2025/07/poor-passwords-tattle-on-ai-hiring-bot-maker-paradox-ai/


The most common passwords for 2025, thus far, are:

123456
123456789
qwerty
password
12345
12345678
111111
1234567
123123
1234567890

https://www.passwordmanager.com/most-common-passwords-latest-statistics/


Now, here's the ridiculous part: it would be pretty trivial for the programmers at Paradox to BLOCK THE USE OF PASSWORDS LIKE THIS! These are common patterns, and it would be easy to test the password and say "NO! You have to use a good password!" There are APIs that enforce good password measures, and clearly they are not using them.

Paradox should be black-listed as a company not to do business with if they allow passwords like this.

Oh, and other Paradox clients? Several Fortune 500 corps including Aramark, Lockheed Martin, Lowes, and Pepsi.

Date: 2025-07-18 05:22 pm (UTC)
ranunculus: (Default)
From: [personal profile] ranunculus
I've been on the internet since the mid-1980's. I have NEVER been dumb enough to use a password like that. A few times (early on) I've used an uncommon word teamed with a symbol for a site that was super low risk, but this breach was not just stupid but criminally stupid.

Date: 2025-07-18 06:24 pm (UTC)
arlie: (Default)
From: [personal profile] arlie
I, on the other hand, routinely use the same almost-that-bad password for any site that imposes "security" on things that don't need it. Web browsers and password safes routinely have kittens about it - large ones with lashing tails. Because of course it would be terrible if someone else played a free solitaire game on my account, or similar.

That said, I agree about McDogFood's security ineptitude. This was not a matter of things that don't matter, except perhaps from the POV from some highly entitled staffer or executive. (Who cares if our applicants' records are leaked? They're just "little people".)

Date: 2025-07-18 08:55 pm (UTC)
ranunculus: (Default)
From: [personal profile] ranunculus
Some years ago there was an excellent article in Wired magazine about passwords. The author had been hacked, his bank accounts emptied and his identity stolen. The hackers first hacked a very unsecure password. At that site they got -just- enough information to up the hack to the next level. From the second, slightly more secure site they got more info. With that info they went in and reset the rest of his passwords. This was easy because the author had then used the -same- password for multiple sites. All told took the hackers perhaps 2 hours to completely wipe him out. The author said he knew he shouldn't have used the same password for multiple sites, but was complacent.
I too don't care if someone else uses my account to play cards, but I do care if they use that site as a stepping stone to hack the rest of my life.

Date: 2025-07-18 09:05 pm (UTC)
arlie: (Default)
From: [personal profile] arlie
It probably helps that I'm inclined to lie like a rug when creating one of those must-create-an-account-to-read-free-article or similar.

I give it a burner email address, that lasts just long enough for the account creation to be verified - deleted when the inevitable spam arrives, if not sooner. And who knows what my name, address and other demographic info look like the day I create the account.

I used to favor rude remarks about overly intrusive demands for information, along with demographics no human would believe. Then I decided I didn't need to even give them that much info. So Israel (Izzy) Forreal has been retired, in favor of semi-random combinations. Though I did enjoy signing up one time as Donald Trump, resident in Antarctica, with a semi-accurate profession.

Come to think of it, these days it's easier to let my software assign a good, unique, password along with the temporarily usable email address. But there was a time ...

Date: 2025-07-18 09:12 pm (UTC)
ranunculus: (Default)
From: [personal profile] ranunculus
My brain is just about random enough to do a good job at password creation. I've seen a random generator generate passwords that were more similar...
Somewhere there is a site that has a wrong birth date for me, exactly because I didn't want to give the correct one. It is amazing where that date turns up.

January 2026

S M T W T F S
    1 23
45 6 7 8910
11121314151617
18192021222324
25262728293031

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 10th, 2026 10:43 am
Powered by Dreamwidth Studios