Anonymous university hack - UPDATE
14 years ago
Well, turns out my password wasn't really leaked, I was just too tired to check it correctly last night.
Still, there was a security breach.
This morning we received an email in our Uni inbox telling us about the leak and there was nothing to worry because the password are encrypted.
I replied, explaining how the passwords weren't encrypted, they were hashed in md5, and that in the Italian University Network there is a nice 2700 GB rainbow table of all md5 hashes, including all of the passwords in that file, so they weren't really safe.
I also told them to hash everything in sha-512, with lots of salt, and to fix the database duplicates...
And they actually thanked me for the heads up, that they'd consider my suggestions.
*MIND. BLOWN*
Still, there was a security breach.
This morning we received an email in our Uni inbox telling us about the leak and there was nothing to worry because the password are encrypted.
I replied, explaining how the passwords weren't encrypted, they were hashed in md5, and that in the Italian University Network there is a nice 2700 GB rainbow table of all md5 hashes, including all of the passwords in that file, so they weren't really safe.
I also told them to hash everything in sha-512, with lots of salt, and to fix the database duplicates...
And they actually thanked me for the heads up, that they'd consider my suggestions.
*MIND. BLOWN*
FA+

Italianfurs