Hacker News new | past | comments | ask | show | jobs | submit login

"hashed passwords (the vast majority with bcrypt) and, in some cases, encrypted or unencrypted security questions and answers"

The went on to say they have unactivated all clear text security questions.

Really, WTF Yahoo. Why bother hashing a pw if you are going to have plaintext security questions.

Though at least they were not using MD5




> Really, WTF Yahoo. Why bother hashing a pw if you are going to have plaintext security questions.

If they had not hashed the passwords you would be able to login to millions of Yahoo accounts with this leaked data.


old accounts. the reason for the "vast majority" and "in some cases" terminology is very likely because the user records only get updated when the user logs in. for accounts that haven't been used in a long long time, it's possible you'd still find pre-bcrypt hashes and plain text question/answers.

Regarding your last sentence, I think other comments have chimed in on what they believe the pre-bcrypt hashes were made with.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: