top | item 44982249

(no title)

boredpudding | 6 months ago

It's solved, full write-up here: https://www.reddit.com/r/MinecraftUnlimited/comments/1cvo5py...

Tl:dr; It was a release file for their Minecon event. It was never meant to be public. Obsessing over a password protected in a company's S3 bucket is weird and crosses many limits.

discuss

order

djmips|6 months ago

Telling people they should not try and crack something is kind of like the Streisand effect.

teruakohatu|6 months ago

> Telling people they should not try and crack something is kind of like the Streisand effect.

More like a reverse-streisand effect. They were honest about the contents of the file, it was Minecraft 1.0 and not interesting, but the community didn't accept the explanation.

cedws|6 months ago

I disagree with this and what Dinnerbone says about locks. It doesn’t matter who file was intended for, it’s on the internet, if people want to use their silicon to do some mathematics to turn some numbers into some other numbers that’s their choice. It’s not equivalent to breaking into a house.

boredpudding|6 months ago

I agree it's not the equivalent, but the file could've contained things like Minecon attendees. That would still mean it's badly secured of course, but putting a huge community effort behind it and youtubers making 'Biggest Secret in Minecraft' videos about it would suddenly turn into very bad taste.

Matthyze|6 months ago

I personally don't see downloadability as a significant factor in the morality of breaching security. If it's bad to hack a login screen to gain access to private information, why wouldn't it be bad to hack encryption to do the same thing? What moral dimension does downloadability alter?

I think the house analogy fails because you cannot duplicate a house, take it somewhere else, and attempt to break into it there. If you could, that would undoubtedly be seen as a violation.

snowram|6 months ago

It is rather common in gaming to communities to find people completely obessed over ultra specific details of their favorite game. It isn't even the first time for Minecraft, see the "pack.png" case.

esnard|6 months ago

Weird. The file was cracked in May 2024, while the password had appeared in a database leak which was added in HIBP (and thus pretty much public) back in October 2017.

Unsure why it took the community so long to crack the file.

catsma21|6 months ago

the salt for the passwords in the bitly breach isn't known, and the few plaintexts available were lost to time

boredpudding|6 months ago

The cracking basically started the moment youtubers presented it as 'a mystery'.

de6u99er|6 months ago

>He mentioned that he does not want people to nag him about it and that “It's brought up every single year, I'm hoping this is the last ”. Finally putting an end to a 13 year old mystery.

Ouch

MortyWaves|6 months ago

I see you haven’t stumbled across the Minecraft community much, because this weirdness is just every day for them.

Take for example, the infamous 2B2T Minecraft server.

Exploits and game breaking mechanics by virtually impossible to discover bugs, and the no rule against hacking and cheating, have led to things people didn’t think were even possible in Minecraft over the servers ~15 year history.

charcircuit|6 months ago

>is weird and crosses many limits.

It's similar in format to communities that obssess over "lost media." The inability to pirate or get access to something becomes an obsession. Even if the piece of media exists in an archive somewhere, that doesn't matter to them because it's about the fact that they themselves don't have access to it that has become the obsession.

LiamPowell|6 months ago

There's also the piracy communities where a majority of users believe they have some sort of inherent right to watch something merely because it exists. I don't understand where that sentiment comes from.

lupusreal|6 months ago

Interest in lost media is a harmless hobby, which occasionally yields positive fruit. Reddit looked for the identity of the song "Subways of your Mind" for 17 years before it was found, and I'm sure the band was pleased to learn their music had found such interest so many years later. Where's the harm? Calling it "obsession" to make it sound bad can be done to any hobby.

neuroelectron|6 months ago

so weird. many limits.

09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0

IT4MD|6 months ago

Thanks for posting that AACS key. It's been awhile since I've seen it running around the internet and we need more of that kind of thing, these days.

aswip|6 months ago

I guess only boxpig41 knows what else was protected that caused them to replace the file just to avoid the chance that the real password might get out and those might be unlocked, though at this point I’m assuming those encrypted files are gone or are no longer important.