4 ms·
Very nice use of password hints. Userwise salted hashes would defeat this attack though.
by user24 13y ago
Very nice use of password hints.
Userwise salted hashes would defeat this attack though.
- frank_boyd 13y ago> salted hashes would defeat this attack though. Seriously. A huge company like Adobe behaving like a beginner in programming? WTF.
- ye 13y agoThat's the biggest WTF about the whole story. I understand leaks and breaches happen, but we've had two decades of them and learned a few things that make DB leaks pretty useless.
- vezzy-fnord 13y agoThey're still better than Yahoo!, who had 450K+ plaintext credentials dumped last year.
- coldcode 13y agoThe best thing about leaking people's databases full of password hashes is teaching people how stupid it is to do it wrong. The worst thing is that most people in charge of this apparently don't read.
- cheald 13y ago> A huge company like Adobe behaving like a beginner in programming? WTF. You are aware that Flash and Acrobat Reader are the attack vectors for something like 50% of all Windows malware, yeah?
- scarmig 13y agoI'm sure you're also aware that, for all Adobe's faults, there's a world of difference between making mistakes writing novel software solutions versus not salting or hashing your passwords. One type of mistake is inevitable on some level, while the other just should not happen.
- oneeyedpigeon 13y ago"novel software solutions" - you work in Adobe's marketing department, right? ;-)
- JeremyBanks 13y agoAdobe's engineering is often pathetic. This is entirely in-line with what I've grown to expect from them.