Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

16 years without reviewing password security seems like a massive oversight. A major leak like this it's a high price to pay to learn this lesson.


The really bad thing is that md5 was considered broken in 2005 by security people like Bruce Schneier.

To be fair to them it took till around 2008 for this to become widespread opinion but the signs were on the wall around 2004


You believe sha256 would drastically improve password hashing, being a not broken hash function? In 2006 they likely ran php4 and didn't have much choice what hash to use.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: