Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This seems to imply that many of (all?) the emails/encrypted passwords were leaked, but you don't consider most of them "compromised"...


I'd like to echo this concern -- were all emails/encrypted passwords leaked, but you only consider those protected by outdated hashing schemes to be compromised?

If so, I feel you have an obligation to alert ALL of your users.


Additional question: when did users first alert you to the hack?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: