|
|
|
|
|
by tempestn
3697 days ago
|
|
Do they say somewhere that they're only using sha1 though? That's sort of what I meant: if bcrypt or scrypt is used, with an appropriate work factor, the risk should be very minimal. The fact that they're assuming it's not suggests they are using weaker encryption. |
|
Unfortunately, the passwords were hashed with the SHA1 hashing algorithm, which by today’s standards is considered weak
Also, hashing != encryption