Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Google once forced a password reset for emails/passwords that leaked from a bitcoin forum.


That's easy to do it you have the email addresses, but impossible to do if you only have the SHA-1 hash, as in this case (unless you're also using unsalted SHA-1 hashes, which is a much bigger issue by itself).


Yes, it's technically easy, but it shows everyone how much Google cares.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: