• Drusas@fedia.io
    link
    fedilink
    arrow-up
    3
    ·
    26 days ago

    The passwords are encoded using the SHA1 cryptographic hash, which is widely considered vulnerable.

    Jesus, they’re not even using SHA-2. It’s been available for ages.

    • starshipwinepineapple@programming.dev
      link
      fedilink
      English
      arrow-up
      0
      ·
      26 days ago

      Even if it was github, they have mandatory 2fa now which would help. Still some risks for people who reuse passwords on other services or if their 2fa got compromised (sim swaps), etc but wouldn’t be full blown catastrophic

        • VeryFrugal@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          25 days ago

          There’s always a chance you get phished and your password as a plaintext gets compromised. Using a same password makes it extra damaging.