←back to thread

410 points gpi | 1 comments | | HN request time: 0.205s | source
Show context
pentagrama ◴[] No.43997245[source]
Maybe it’s a naive question, but in many breach reports I see things like 'No passwords, private keys, or funds were exposed.' How come companies can usually protect that kind of data, but not emails, names, and other personal info?
replies(4): >>43997258 #>>43997270 #>>43997935 #>>43998132 #
1. wat10000 ◴[] No.43997935[source]
A properly implemented login system will never store a password in the first place. Properly hashed passwords can still be cracked in some cases, but if your password is strong and the hash is good, it’s safe.