Well even if the breech wasn't an attack via account compromise. The fact is the password hashes were STOLEN. And, they CAN be decrypted with the proper tools, time and effort. Although it would need to be a targeted attack for a certain member to go that far.
As for encryption, SHA1 should be used and I would've though vB5 would have it. Guess one more thing that IB failed at once again....
|