• AndyMFK
    arrow-up
    24
    arrow-down
    0
    ·
    6 days ago
    edit-2
    6 days ago
    link
    fedilink

    Haven’t looked much into the breach, but probably the biggest issue is passwords. If unencrypted, and a user uses the same generic password for their email or bank or whatever, that possess a serious concern.

    This highlights the importance of not reusing passwords

    Edit: looks like passwords were hashed with bcrypt, which is really quite excellent. Very unlikely anybody is getting actual passwords from this leak.

    • Quail4789English
      arrow-up
      4
      arrow-down
      0
      ·
      6 days ago
      link
      fedilink

      If someones reusing their passwords then their passwords will likely be found very easily with rainbow tables.

        • ipkpjersi
          arrow-up
          2
          arrow-down
          0
          ·
          6 days ago
          link
          fedilink

          Which bcrypt does, since it generates a unique salt per-password.

      • Sneezycat
        arrow-up
        2
        arrow-down
        0
        ·
        6 days ago
        edit-2
        6 days ago
        link
        fedilink

        If your password is long/complex enough, it ain’t going to be on a rainbow table. But yeah.

        • Quail4789English
          arrow-up
          1
          arrow-down
          0
          ·
          6 days ago
          link
          fedilink

          People reusing passwords probably also aren’t using long and complex passwords.

          • Sneezycat
            arrow-up
            3
            arrow-down
            0
            ·
            6 days ago
            link
            fedilink

            why not? they may have one long pass that they remember and use for everything, can’t be bothered to remember more of them.

            • XTL
              arrow-up
              3
              arrow-down
              0
              ·
              6 days ago
              link
              fedilink

              That’s probably correct, horse battery staple.

    • ipkpjersi
      arrow-up
      1
      arrow-down
      0
      ·
      6 days ago
      link
      fedilink

      I’d hope that passwords would be unencrypted, really they should be hashed ;)