• AndyMFK
      arrow-up
      24
      arrow-down
      0
      ·
      6 days ago
      edit-2
      6 days ago
      link
      fedilink

      Haven’t looked much into the breach, but probably the biggest issue is passwords. If unencrypted, and a user uses the same generic password for their email or bank or whatever, that possess a serious concern.

      This highlights the importance of not reusing passwords

      Edit: looks like passwords were hashed with bcrypt, which is really quite excellent. Very unlikely anybody is getting actual passwords from this leak.

      • Quail4789English
        arrow-up
        4
        arrow-down
        0
        ·
        6 days ago
        link
        fedilink

        If someones reusing their passwords then their passwords will likely be found very easily with rainbow tables.

          • ipkpjersi
            arrow-up
            2
            arrow-down
            0
            ·
            6 days ago
            link
            fedilink

            Which bcrypt does, since it generates a unique salt per-password.

        • Sneezycat
          arrow-up
          2
          arrow-down
          0
          ·
          6 days ago
          edit-2
          6 days ago
          link
          fedilink

          If your password is long/complex enough, it ain’t going to be on a rainbow table. But yeah.

          • Quail4789English
            arrow-up
            1
            arrow-down
            0
            ·
            6 days ago
            link
            fedilink

            People reusing passwords probably also aren’t using long and complex passwords.

            • Sneezycat
              arrow-up
              3
              arrow-down
              0
              ·
              6 days ago
              link
              fedilink

              why not? they may have one long pass that they remember and use for everything, can’t be bothered to remember more of them.

              • XTL
                arrow-up
                3
                arrow-down
                0
                ·
                6 days ago
                link
                fedilink

                That’s probably correct, horse battery staple.

      • ipkpjersi
        arrow-up
        1
        arrow-down
        0
        ·
        6 days ago
        link
        fedilink

        I’d hope that passwords would be unencrypted, really they should be hashed ;)

    • JohnyRocket
      arrow-up
      3
      arrow-down
      0
      ·
      6 days ago
      link
      fedilink

      Hopefully they didn’t store to much financial info from donations, otherwise I am a bit coocked