this post was submitted on 03 Jan 2024
108 points (94.3% liked)

Cybersecurity

5753 readers
475 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
 

They're blaming customers for not having good cybersecurity practices instead of themselves for not having good cybersecurity practices.

you are viewing a single comment's thread
view the rest of the comments
[–] brbposting 2 points 10 months ago (2 children)

Shouldn’t service providers be hashing the plaintext passwords that show up in dark web leaks to see if matching users reused those passwords?

[–] [email protected] 4 points 10 months ago

Wouldn’t really be of any use if they’re doing things right and salt their hashes

[–] sugar_in_your_tea 3 points 10 months ago

They typically do, but that doesn't stop hackers from posting the plaintext.

The real solution is to never store plaintext and to use MFA.