Hacker News new | ask | show | jobs
by benlivengood 1855 days ago
Reused passwords are also really common and so cracking new dumps of salted and hashed passwords will yield a pretty high success rate.

At this point I just assume that any password that's been leaked (hashed or not) is in plaintext in some database. Obviously 20-character random passwords aren't going to get reversed but there's no guarantee that they were always hashed and weren't leaked from the login process itself, etc.