Hacker News new | ask | show | jobs
by sneeds 1608 days ago
> The site was created in 2006 with little knowledge of security, so passwords were stored in md5() hashes without salt Sorry, but this is no excuse. It has been 15 years and there were so many breaches that even many casual people know about databases leaks and that passwords have to be stored in some special way. I don't know this guy's background, but he at least knows that md5 is not sufficient here. And then it never crossed his mind to do a check up on this? That's just negligent.
1 comments

to his defense it's not like there is anything serious stored there with those accounts, it's just subtitles
It's not just subtitles - it's all the login information stored there as well. Email addresses to send spam to, passwords that have likely been reused on another site.
and how is you reusing password to download subtitles (it ain't even necessary really) problem of the hacked site?

yes spam could be annoying, but it's not like people use email only to register on one site