This one appears (2nd report this year) to be a real
doozy too, in sheer size and scope.
It is my understanding that as these breaches happen the problem becomes worse because now the hackers have more data to use in their brute force attacks. So each breach makes all of us less secure, indviduals and corporations. Arstechnica had a 2012 article about a password-cracking expert that had put together a computer cluster that could process 350 billion guesses per second. They said at the time that every possible Windows passcode could be tried in less than six hours. 95^8 combinations in just 5.5 hours, enough to brute force every possible eight-character password containing upper- and lower-case letters, digits, and symbols. Yahoo just learned data loss occurred in 2013 but doesn't know how long they were actually compromised (at least not saying). Those passwords were hacked a long time ago, especially if they are only using MD5 hashing.
If one reads
zdnet security section, it's really frustrating. This is a HUGE problem that is getting too little attention. What good is anything that uses the Internet if it isn't secure (this includes IoT devices) and can be hacked. :-(
Quote:
My greatest fear is that, rather than having a cyber-Pearl Harbor event, we will instead have this death of a thousand cuts.
http://www.zdnet.com/article/richard-clarke-china-has-hacked-every-major-us-company/ PS: I came here to read about gimpchat security, but more so remove my yahoo email.... Argh! :-)