3 ms·
I find it hard to believe that they didn't know better. They were using 12 rounds of bcrypt to store the passwords, afterall. Assuming just the DB is compromise
by ssharp 11y ago
I find it hard to believe that they didn't know better. They were using 12 rounds of bcrypt to store the passwords, afterall. Assuming just the DB is compromised, they would likely be okay because of that. I'm not sure how often systems are so entirely pwned as to gain access to their source code repos and their entire production database. That seems like an outlier kind of attack, though I think the same thing happened with Sony.
I don't think it's fair to say that this was a security oversight, so much as it was a conscience decision to make the system have less friction for users by utilizing these login tokens.