3 ms·
Reading the official news release [1], the cynic in me thinks the wording of just "password" indicates that these were plain text passwords. From my experience,
by imposterr 7y ago
Reading the official news release [1], the cynic in me thinks the wording of just "password" indicates that these were plain text passwords. From my experience, when the passwords are hashed/salted, the companies make it a point to include that.
[1] https://www.lifelabs.com/lifelabs-releases-open-letter-to-customers-following-cyber-attack/ https://www.lifelabs.com/lifelabs-releases-open-letter-to-cu...
- slantyyz 7y agoI think the big concern is the presumption of a non-techie that a medical company would take good care of their information, because of regulations, etc. I would not be surprised if a LOT of Lifelabs customers used the same password on their Lifelabs accounts that they use for their email. FWIW, Lifelabs has two sub-sites that use different credentials - one for test results, and one for booking appointments.