My dumbass read “github” and I had a small heart attack.
TheButtonJustSpins@infosec.pub
on 10 Apr 14:09
nextcollapse
I was right there with you
starshipwinepineapple@programming.dev
on 10 Apr 19:38
collapse
Even if it was github, they have mandatory 2fa now which would help. Still some risks for people who reuse passwords on other services or if their 2fa got compromised (sim swaps), etc but wouldn’t be full blown catastrophic
threaded - newest
My dumbass read “github” and I had a small heart attack.
I was right there with you
Even if it was github, they have mandatory 2fa now which would help. Still some risks for people who reuse passwords on other services or if their 2fa got compromised (sim swaps), etc but wouldn’t be full blown catastrophic
I thought the point of salting was that the reuse doesn’t matter as much?
There’s always a chance you get phished and your password as a plaintext gets compromised. Using a same password makes it extra damaging.
Jesus, they're not even using SHA-2. It's been available for ages.
Move fast and break things!
“Things” in many cases includes “security”.
Bro…