Hacker News new | ask | show | jobs
by thetabyte 5003 days ago
So, I'm at the University of Maryland right now. All three mirrors seem to be down, so I couldn't check if my information was on the list. The article suggests this was done with SQL injection? God, I really hope my university is better than that. Or at least hashes passwords. I'd check if they did, but again, mirrors seem to be down. Sad thing is, I wouldn't be surprised. Despite the 15th best comp sci program in the nation, and ridiculous policies like "change you password to new unique password with at least 1 number and capital letter every 180 days", OIT seems useless on security. Sigh.
2 comments

I haven't looked at all the data released, but for the sample I did look I didn't see a breach of a university's central records system - they were breaches of things like the university's diving club's phpbb forum.

Fairly mundane as these things go.

There was at least one university where hashed passwords were leaked. I believe it was michigan, though not sure anymore.