|
|
|
|
|
by argsv
1686 days ago
|
|
I don't trust the first release or the first disclosure. I expect Robinhood in the next few days to disclose that the exposure was wider and more serious than initially thought. It also seems that they don't encrypt social security numbers and other sensitive data; I imagine if they did they would have mentioned it. Their track record isn't that of a company to be trusted. |
|
Brute forcing this order of difficulty was considered "done" around 2014 for SHA-1. I suppose you could add enormous number of recursive hashes or an immensely expensive parameter selection for bcrypt. But I feel most realworld implementations of hashed SSN would be only little better than plaintext.