8 ms·
> The site was created in 2006 with little knowledge of security, so passwords were stored in md5() hashes without salt Sorry, but this is no excuse. It has bee
by sneeds 5y ago
> The site was created in 2006 with little knowledge of security, so passwords were stored in md5() hashes without salt
Sorry, but this is no excuse. It has been 15 years and there were so many breaches that even many casual people know about databases leaks and that passwords have to be stored in some special way. I don't know this guy's background, but he at least knows that md5 is not sufficient here. And then it never crossed his mind to do a check up on this? That's just negligent.
- Markoff 5y agoto his defense it's not like there is anything serious stored there with those accounts, it's just subtitles
- mnw21cam 5y agoIt's not just subtitles - it's all the login information stored there as well. Email addresses to send spam to, passwords that have likely been reused on another site.
- Markoff 5y agoand how is you reusing password to download subtitles (it ain't even necessary really) problem of the hacked site? yes spam could be annoying, but it's not like people use email only to register on one site