Hacker News new | ask | show | jobs
by protocow 3396 days ago
Or c-level executives will remember this tidbit before they let their security folks talk them into a password reset after a breach. You have to wonder whether a company in that situation has other options, like blocking logins from previously unseen IPs (for users who don't change passwords).
1 comments

You think a company that was using SHA1 [0] to hash passwords was actually logging IP addresses?

[0] - https://arstechnica.com/security/2013/04/why-livingsocials-5...