Alleged leak of 270k user e-mails + unsalted MD5 password hashes (!!!) from popular sim racing service Trading Paints (twitter.com)
from sunaurus@lemm.ee to cybersecurity@sh.itjust.works on 28 Aug 2023 12:46
https://lemm.ee/post/5767342

#cybersecurity

threaded - newest

sunaurus@lemm.ee on 28 Aug 2023 12:50 next collapse

Assuming the leak is real (I did not attempt to verify if any of the leaked passwords work myself): why the heck are popular services in 2023 still using MD5?

I’m also really disappointed by the fact that many users & even many admins (people with @iracing.com and @tradingpaints.com e-mail addresses) clearly don’t use password managers.

hoodlem@hoodlem.me on 28 Aug 2023 13:14 collapse

Unsalted. And MD5? Ugh ugh ugh. Feel so bad for the thousands of these folks that re-use the same password for important email accounts and banking.

Password managers are a must today.