Hacker News new | past | comments | ask | show | jobs | submit login

Well, since Steam only stores the salted PW hashes, it doesn't seem like that would allow them to compromise your facebook account.



Salting a password doesn't make it uncrackable, it just makes it impervious to rainbow tables and other parallel attacks because it forces the attacker to recalculate the hash for every guess for every user account. You can certainly still run a mangled dictionary attack on a salted database, it will just take a lot longer.


It was hardly an uncrackable password :)

I hadn't really used either account in years, so I never got around to enhancing my passwords.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: