I have an eBay account, but I haven't used it in years, and I doubt I remember the password. How worried about this should I be? Are there plaintext passwords exposed, or do they just have a lot of properly salted hashes that aren't much use to an attacker?
The passwords look like this: pbkdf2_sha256$12000$zhMKabMgayvK$iniviUCcX9y2PYJcm0AoB3MhybRA1z2Cec1DZnLWxWc= I do not know how much time it would take to bruteforce these. Can any experienced HNers weigh in?
Since these are salted and require 12000 iterations, cracking individual passwords will be quite time consuming. The preferred method in this case, though, is to go after low hanging fruit.
The way one would do this is to try something like the 500 most common passwords against all entries in the table. This won't take very long (compared to trying to brute force a bunch of individual passwords), and will probably yield a ton of passwords.