Hacker News new | ask | show | jobs
by dlau1 4263 days ago
IMO service providers should, at the very least, have procedures in place to lock the accounts in the list then email everyone with an unlock link.

I just can't fathom there being huge publicly available password lists with credentials that are still valid.