5 ms·
They should mention if the passwords were salted or not. Just saying the passwords were hashed isnt sufficient.
by redditmigrant 9y ago
They should mention if the passwords were salted or not. Just saying the passwords were hashed isnt sufficient.
- wapz 9y ago> we encourage you to change your password for any other services where you are using the same password Based on that statement it sure doesn't sound like the PWs were salted (or at least properly salted).
- deleted 9y ago[deleted]
- wapz 9y agoSo can someone explain to me why the downvotes? If the salts are unique to the user wouldn't it be nearly impossible for the hacker to use the hashed pw on other sites? (I'm not a web dev but to my understanding that's how it works)
- ktta 9y agoEven if salts are unique to a single user, there's still a possibility where someone determined can get the password. That's because the user specific salts were probably in the same db. This will make it difficult since a brute force attack must be done for every single password. But it is still not impossible.
- sudshekhar 9y ago> If the salts are unique to the user wouldn't it be nearly impossible for the hacker to use the hashed pw on other sites Even if the salts aren't unique, can you explain how can they use the hashed password anywhere? If I give you a hashed password and the salt used, what exactly can you do with it? (apart from brute forcing)
- MichaelGG 9y agoFor instance, you can make a list of the top 100,000 passwords, plus another 1000-per-user variations (based on username or email or whatever). Now run them against all users. You'll get some successes, and now those users are at risk. A password DB breach, salted or not, allows an offline, non-rate-limited, attack on those passwords.
- kranner 9y agoThey do mention it: "We hash passwords with a one-way hashing algorithm, with multiple hashing iterations and individual salt per password."
- abhi3 9y agoSo is my password safe?
- deleted 9y ago[deleted]
- kranner 9y agoMaybe, if they are being truthful. Hopefully you don't share it with another account on another site.
- sho 9y ago> Hopefully you don't share it with another account on another site Bluntly, for a user of a site like this in 2017 there is simply no excuse for sharing passwords. In ops we used to say "If it's not backed up, it doesn't exist" - and I think a modern corollary could be "if your password isn't unique per site, then no, it's not safe". If you reuse passwords, your security is only as good as the weakest site you used it on, and you are playing with fire. Just go and buy 1password (or similar) and use it.
- thatwebdude 9y ago> "with multiple hashing iterations and individual salt per password." If your username is...
- Jackalopiate 9y agoProbably? The hacker is working with them and claims to have deleted all of the info already. read their updated article, its an interesting development
- redditmigrant 9y ago