All 32mil RockYou accounts hacked. Passwords were stored in plaintext.
1–10 of 112 posts
Re: All 32mil RockYou accounts hacked. Passwords were stored in plaintext.
#2The right answers to this problem are BCrypt, SCrypt, PBKDF, or (at a minimum) salted "stretched" SHA1, iterated many thousands of times.
Re: All 32mil RockYou accounts hacked. Passwords were stored in plaintext.
#3Re: All 32mil RockYou accounts hacked. Passwords were stored in plaintext.
#4if true, this is so irresponsible it is almost unbelievable
Re: All 32mil RockYou accounts hacked. Passwords were stored in plaintext.
#5Re: All 32mil RockYou accounts hacked. Passwords were stored in plaintext.
#6Re: All 32mil RockYou accounts hacked. Passwords were stored in plaintext.
#7Re: All 32mil RockYou accounts hacked. Passwords were stored in plaintext.
#8Re: All 32mil RockYou accounts hacked. Passwords were stored in plaintext.
#9This is just some amateur hour shit. They're a well established and well funded company. How do venture funds not do better technical due diligence(or any at all)? I wouldn't release an app for 32 of my friends to test, let alone 32 million people to use with plain text passwords. Enough of my bitching, because it's inaction. Now for words of action/openings for suggestion: How do we make sure companies don't do dumb…
Re: All 32mil RockYou accounts hacked. Passwords were stored in plaintext.
#10Note that if you store your passwords in a fast hash format like salted SHA1, an attacker with 32MM database rows can publish a very credible sample of usernames and passwords, and leave you scrambling to explain how the breach isn't really as bad as it looks. Not a great position to be in. The right answers to this problem are BCrypt, SCrypt, PBKDF, or (at a minimum) salted "stretched" SHA1, iterated many thousands…