3 ms·
I'm curious about how the hack occurred. With the recent Hipchat hack, it is unclear if the login server was compromised or the database dump was obtained some
by narsil 9y ago
I'm curious about how the hack occurred.
With the recent Hipchat hack, it is unclear if the login server was compromised or the database dump was obtained some other way.
If the Hipchat webserver that handles sign-in attempts was the one compromised, which is what I've been lead to believe, then it doesn't matter how the passwords were hashed. The plain-texts would be exposed in the majority of use cases. Sure, the DB data could also get stolen triggering reporting requirements in organizations with controls, but that may be less of a concern at that point.