Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Correct, that's why we couldn't post a list of affected sites or malicious actors would immediately abuse it :/


It seems reasonable to assume that the exposed information has already fallen into the wrong hands. Might as well post the list at this point (or at some point, at least) so that any users of those sites can become aware, no?


Shouldn't encrypting all databased records be the only sane, safe and legal solution with decryption key sent to local (to the website owner) law enforcement when site owners aren't responsive?

Not saying you should do that given the current state of the laws.


It'll now take them 2-3 weeks to get the details.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: