3 ms·
TL;DR: Here's what happened. When a password reset is submitted, the user receives a random URL by email containing a random 21 letter string. The algorithm use
by adorable 13y ago
TL;DR: Here's what happened.
When a password reset is submitted, the user receives a random URL by email containing a random 21 letter string. The algorithm used was bad, so the random string could be brut-forced.
The OVH team researched 3 years of password changelogs and found 3 customers who had been brute-forced that way, all in the "bitcoin community"