|
|
|
|
|
by bri3d
4459 days ago
|
|
What's potentially scarier than plaintext passwords leaking out is that key material leaks as well. 64k of random memory is bad, 64k of OpenSSL's state is worse. Also, why haven't Yahoo taken down their login service yet? I really don't see how leaving your users' passwords leaking in plaintext is ever better than downtime. Someone had to have made that call, and I really don't think it was the right one. Will be interesting to see how the media treats this over the next few days. EDIT: Looks like Yahoo is finally fixed. Wonder how many accounts were compromised in the interim, and if their cert and private key were compromised as well. Does not look like they've re-issued yet. |
|