Got an email from Yahoo this morning about this... >:(
Quote
Internet giant Yahoo announced a massive data breach Wednesday that affected over one billion accounts :wow:, making it by far the largest data breach in history. This follows the disclosure in September of a different breach that affected more than 500 million of the company's customers.
What stands out with this new security compromise is that it occurred over three years ago, in August 2013, and that hackers walked away with password hashes that can be easily cracked.
http://www.pcworld.com/article/3150953/security/5-things-you-should-do-following-the-yahoo-breach.html
They were still using MD5 for hashing. Even for 2013, that's inexcusably weak.
My Yahoo email address is my oldest and most widely circulated. It would be a pain to stop using, but it may be time. Yahoo's security is atrocious.
If I'm reading this right the breach occurred three years ago? I've changed my passwords not too long ago so I should be ok?
Quote from: bbmike on December 15, 2016, 11:02:13 AM
If I'm reading this right the breach occurred three years ago? I've changed my passwords not too long ago so I should be ok?
You should be okay. Yahoo recently did a forced password change for all users (which is when I knew they were screwed).
The main thing is not to reuse passwords. Especially for anything mission critical (banking, etc).
Thanks. I really wish someone would come up with a better way for security than all these passwords. :uglystupid2: