6 ms·
Wait, "Password" was stolen? WTF they store unencrypted passwords?!?!?!!?! I sure hope they meant password hashes otherwise upset many people should be.
by GrandMasterBirt 15y ago
Wait, "Password" was stolen? WTF they store unencrypted passwords?!?!?!!?! I sure hope they meant password hashes otherwise upset many people should be.
- nuclear_eclipse 15y agoEven if hashes are stolen, you should consider the original password stolen as well, because it's only a matter of time and effort to brute force the original password from the hash. Even if you use a really good password with a really good hash (like bcrypt), it still doesn't mean that they can't find the password, just that it will take more time to do so.
- derobert 15y agoA really good password with a really good hash takes more time for values of time exceeding far exceeding any human's lifespan. Assuming a 10-character random alphanumeric, that'd be 62¹⁰ possibilities (26 uppercase + 26 lowercase + 10 numbers = 62). Even given an insanely fast brcypt of 1µs, that's over thirteen thousand years to get to a 50% chance. Now, if your hash is a bad one, say MD5, then you're in trouble. GPUs could brute force that ten-character password within a year.