I've changed my Tumblr password after this just in case, but it was some approximately hundred character random password generated by Lastpass before that.
So let's say half the ASCII range, which gives us this number of possible passwords:
(2^7/2)^100
41495155688809929585124078636911611510124462322424368999956573296906\
52811412908146399707048947103794288197886611300789182395151075411775\
307886874834113963687061181803401509523685376.00000000000000000000
I'm pretty sure even if it's just stored as single-iteration sha1() cracking it would take until the heat death of the universe.Still, the hash time for a SHA1 is fairly insignificant at this point.
It's much better than plaintext, but essentially only a little bit better than unsalted MD5.
I'm really surprised Tumblr would use such an awful password storage scheme as late as 2013. I thought they invested a lot into security?
I consider precomputed attacks a special case of these attacks, sort of. In the security world, most password-predicting attacks are linear with respect to the amount of accounts you're trying to get passwords for.
It's true that it will take a lot of hardware to efficiently attack all 65 million passwords. But in my field, big dumps like these are a godsend when doing a pentest.
Looking to compromise a sysadmin's account? Search his/her emails and aliases in as many DB dumps as you can find, then expend a lot of resources cracking that one hash. If it's just a SHA-1 hash and the password isn't very strong, you won't have much trouble.
Also a risk for people with vendettas against specific tumblr users (which, to my understanding, is a big issue on tumblr).
At least one major benefit of SHA over MD5 is that you won't trivially find collisions and thus compromise the accounts of even those users with strong passwords...