Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: cymbeline
All of that inconveniences users, and won't solve the problem described in the article:

hacked their way into the social app website’s servers and got their hands on more than 32 million user passwords stored in plain text

Correct best-practice is not to store the password at all, but to store a "salted hash" of the password. That's why a correctly designed site will let you update your password, but can't tell you what your current password is -- they don't have it.

If you have to store a password -- you shouldn't, but if you did -- then it needs to be stored encrypted. Ditto for high-security data like SSNs, etc.

If there's a 99% cause of hacking, it's people running stuff they get as email attachments. For awhile, M$ Outlook even ran such stuff automatically! Talk about a security hole!

23 posted on 06/09/2021 7:41:22 AM PDT by Campion (What part of "shall not be infringed" don't they understand?)
[ Post Reply | Private Reply | To 7 | View Replies ]


To: Campion

“If there’s a 99% cause of hacking, it’s people running stuff they get as email attachments.”

Maybe so. I’m not an expert. You’d think it would be possible at the administrative level to prohibit running any non-authorized program. I know that would be an inconvenience.


34 posted on 06/09/2021 8:29:26 AM PDT by cymbeline
[ Post Reply | Private Reply | To 23 | View Replies ]

To: Campion

Yeah, they’re not getting millions of passwords by hacking millions of personal computers. They’re hacking Yahoo, Apple etc who so kindly stores your passwords for you on their systems.


41 posted on 06/09/2021 9:36:26 AM PDT by Pollard
[ Post Reply | Private Reply | To 23 | View Replies ]

To: Campion
Correct best-practice is not to store the password at all, but to store a "salted hash" of the password. That's why a correctly designed site will let you update your password, but can't tell you what your current password is -- they don't have it.

Yup. Any system that can send you a copy of your password is fundamentally broken and shouldn't be trusted.

57 posted on 06/09/2021 11:30:59 AM PDT by zeugma (Stop deluding yourself that America is still a free country.)
[ Post Reply | Private Reply | To 23 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson