this post was submitted on 10 Apr 2025
43 points (97.8% liked)

Cybersecurity

7057 readers
29 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
top 8 comments
sorted by: hot top controversial new old
[–] [email protected] 27 points 2 weeks ago (2 children)

My dumbass read "github" and I had a small heart attack.

[–] [email protected] 5 points 1 week ago

I was right there with you

[–] starshipwinepineapple 2 points 1 week ago (1 children)

Even if it was github, they have mandatory 2fa now which would help. Still some risks for people who reuse passwords on other services or if their 2fa got compromised (sim swaps), etc but wouldn't be full blown catastrophic

[–] [email protected] 1 points 1 week ago (1 children)

I thought the point of salting was that the reuse doesn't matter as much?

[–] [email protected] 3 points 1 week ago

There's always a chance you get phished and your password as a plaintext gets compromised. Using a same password makes it extra damaging.

[–] [email protected] 8 points 1 week ago (1 children)

The passwords are encoded using the SHA1 cryptographic hash, which is widely considered vulnerable.

Jesus, they're not even using SHA-2. It's been available for ages.

[–] [email protected] 1 points 1 week ago

Move fast and break things!
"Things" in many cases includes "security".

[–] [email protected] 5 points 1 week ago

The passwords are encoded using the SHA1 cryptographic hash,

Bro..