RE: DailyMotion got hacked 12-06-2016, 02:29 PM
#4
(12-06-2016, 02:22 PM)mothered Wrote:(12-06-2016, 12:29 PM)Pikami Wrote: At least they are not plain text
Bcrypt hashing is so slow that nobody will bother cracking the hashes
Yes, storing user-credentials In plain text Is just sheer stupidity.
During my exploitations, you wouldn't believe how many passwords and PIN codes I've comes across In plain text. I have hundreds on hand from Individual sites- all saved with unedited screenshots. Bcrypt (key stretching) can prove to be quite effective against bruteforcing and the like, even when powerful GPUs are used In attacks. On topic, DailyMotion's security breach just demonstrates that the nature of the website (pretty much superior on securing It's data), has no bearing against dedicated hackers and attacks. That Is, anyone and anything with an Internet connection Is vulnerable to exploitation.
Oh, I believe you, lots of websites still store passwords in plain text and anything can be exploited if you have enough resources. That's how everything works. It's just nice to see a company that uses great hashing techniques for storing passwords instead of using MD5 witch isn't even created for password hashing...













![[Image: 9H83e18.png]](https://i.imgur.com/9H83e18.png)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)