Live data from Hacker News

xkcd: 562k Accounts breached according to haveibeenpwned

twitter.com

1–10 of 16 posts

Re: xkcd: 562k Accounts breached according to haveibeenpwned

#2
I'm one of them :/

The haveibeenpwned description says password hashes are md5, which sucks. But phpBB has used bcrypt by default since version 3.1 (2014)... I wonder if all the hashes are md5 or only those for older accounts?

https://haveibeenpwned.com/PwnedWebsites#XKCD

Re: xkcd: 562k Accounts breached according to haveibeenpwned

#4

I'm one of them :/ The haveibeenpwned description says password hashes are md5, which sucks. But phpBB has used bcrypt by default since version 3.1 (2014)... I wonder if all the hashes are md5 or only those for older accounts? https://haveibeenpwned.com/PwnedWebsites#XKCD

Impacted as well, but I'm happy to be part of it. Either they'll crack an old password or, more likely, this is a new style password and they waste a lot of cracking time on it. Using a password manager for everything except a few offline things and my bank account was definitely the right move.

Re: xkcd: 562k Accounts breached according to haveibeenpwned

#8
post #4

I'm one of them :/ The haveibeenpwned description says password hashes are md5, which sucks. But phpBB has used bcrypt by default since version 3.1 (2014)... I wonder if all the hashes are md5 or only those for older accounts? https://haveibeenpwned.com/PwnedWebsites#XKCD

Impacted as well, but I'm happy to be part of it. Either they'll crack an old password or, more likely, this is a new style password and they waste a lot of cracking time on it. Using a password manager for everything except a few offline things and my bank account was definitely the right move.

What do you use for your bank account?
Post reply on HN