What's shocking to me is that Yahoo! still uses MD5 hashes. Those can be decrypted almost instantly with hashcat and tools like it. There's some confusion about the age of data in question but I hope they've moved away from MD5 since the breach occurred.