Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What?!

This means next leak will be one million CRC32 password hashes?

Or maybe LM hashes. Or crypt on old /etc/password files



This was funny, and I laughed, but the irony is that old Unix crypt(3) is probably better than MD5 or SHA1.


ROT13?


Ive seen a legacy application still in use which puts the password in a (non-secure) cookie as ROT13 and cleartext in the db.


Don't forget last year around this time when Sony's PSN was cracked into and it turned out they were storing the cleartext passwords.


Well, the Gawker hack was DES IIRC.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: