5 ms·
Just assume that it's compromised and generate a new one. There is no point in wasting time trying to estimate how long it might take someone to crack it.
by trulyrandom 7y ago
Just assume that it's compromised and generate a new one. There is no point in wasting time trying to estimate how long it might take someone to crack it.
- viraptor 7y agoIt matters at lower extreme. If it was something trivial and people shared the password with another account, then they may be already compromised. If it was hard and salted per-user, they still have to change it, but the chance of compromise on other services is significantly lower. It may also explain some suspicious behaviour / source of compromise in the past (we know when the issue was uncovered, not when the first dump was taken)