Live data from Hacker News

Adobe confirms stolen passwords were encrypted, not hashed

csoonline.com

1–10 of 112 posts

Re: Adobe confirms stolen passwords were encrypted, not hashed

#6
post #4

Adobe says that they've followed best practices for password storage and protection for more than a year now... 13 generations of photoshop ...and they're just getting around to this after CS6?

I wouldn't call Photoshop an achievement, it's a hodgepodge of old libraries and bugs at the best of times.

Adobe refused to patch a vulnerability in CS5 at one point, telling people to purchase and upgrade to CS6 (US$199) if they wanted to not be vulnerable to malicious code execution. In response to the uproar they eventually backported the patch.

[0]: http://www.macworld.com/article/1166779/adobe_will_issue_fre...

Re: Adobe confirms stolen passwords were encrypted, not hashed

#7
post #4

Adobe says that they've followed best practices for password storage and protection for more than a year now... 13 generations of photoshop ...and they're just getting around to this after CS6?

What does Photoshop have to do with their poor security?

Re: Adobe confirms stolen passwords were encrypted, not hashed

#8
post #6
post #4

Adobe says that they've followed best practices for password storage and protection for more than a year now... 13 generations of photoshop ...and they're just getting around to this after CS6?

I wouldn't call Photoshop an achievement, it's a hodgepodge of old libraries and bugs at the best of times. Adobe refused to patch a vulnerability in CS5 at one point, telling people to purchase and upgrade to CS6 (US$199) if they wanted to not be vulnerable to malicious code execution. In response to the uproar they eventually backported the patch. [0]: http://www.macworld.com/article/1166779/adobe_will_issue_fre...

Not a constructive comment, sorry, but I couldn't help chuckle reading this. It's beyond ridiculous.

Re: Adobe confirms stolen passwords were encrypted, not hashed

#9
post #4

Adobe says that they've followed best practices for password storage and protection for more than a year now... 13 generations of photoshop ...and they're just getting around to this after CS6?

What does Photoshop have to do with their poor security?

I think the point is that they've had plenty of time to get their shit together. Being proud of following best practices for a year when your company has been around for three decades is pathetic.
Post reply on HN