3 ms·
Even if passwords are salted and hashed, easily guessed passwords can still be brute forced (think password123). Even with good password hashing algorithms like
by tkems 3y ago
Even if passwords are salted and hashed, easily guessed passwords can still be brute forced (think password123). Even with good password hashing algorithms like PBKDF2 (I have no idea what Comcast was using, but this is what LastPass uses) with a high cost value, this can be attempted for the most common passwords fairly quickly.
This also occurs 'offline', meaning that an attacker doesn't have to attempt to login to the webpage to try to brute force the passwords, it happens all on the attackers machine because they have a copy of the database.
On top of this, lots of people reuse passwords which makes this an attractive target for such attacks.