Live data from Hacker News

Adobe confirms stolen passwords were encrypted, not hashed

csoonline.com

11–20 of 112 posts

Re: Adobe confirms stolen passwords were encrypted, not hashed

#16
post #8
post #6

Earlier quoted context omitted.

I wouldn't call Photoshop an achievement, it's a hodgepodge of old libraries and bugs at the best of times. Adobe refused to patch a vulnerability in CS5 at one point, telling people to purchase and upgrade to CS6 (US$199) if they wanted to not be vulnerable to malicious code execution. In response to the uproar they eventually backported the patch. [0]: http://www.macworld.com/article/1166779/adobe_will_issue_fre...

Not a constructive comment, sorry, but I couldn't help chuckle reading this. It's beyond ridiculous.

Mammoth corporations have fuck-all to do with common sense. They're run by apathetic shills that couldn't care less about technology, progress, or people (not to knock the talent that works in the trenches).

Re: Adobe confirms stolen passwords were encrypted, not hashed

#20
post #4

Adobe says that they've followed best practices for password storage and protection for more than a year now... 13 generations of photoshop ...and they're just getting around to this after CS6?

I'm curious to hear when exactly people think bcrypt became accepted best practice? And how much of a grace period did people have to switch? Were you incompetently negligent if you didn't use bcrypt by 2003? 2007? 2011?

(I ask this as a fairly big fan of bcrypt myself. Somehow I just have the impression that half the peanut gallery comments come from people who literally switched over from md5 hashes yesterday and suddenly feel the need to crow about their great accomplishment.)

Post reply on HN