UPDATE: looks legit.
http://forum.bitcoin.org/index.php?topic=19543.0
https://support.mtgox.com/entries/20208066-huge-bitcoin-sell...
UPDATE: looks legit.
http://forum.bitcoin.org/index.php?topic=19543.0
https://support.mtgox.com/entries/20208066-huge-bitcoin-sell...
Some passwords are md5 hashes, some are salted md5 hashes (utilizing the crypt[0] function). I did not log in for a long time and my password was still unsalted, so I assume that converting to salted passwords was done either automatically on login or on password changes.
0: http://www.kernel.org/doc/man-pages/online/pages/man3/crypt....
http://www.schneier.com/book-applied.html
Edit: Note, this really barely scratches the surface for building secure software. AC says how to apply cryptographic primitives correctly. It won't teach you how to avoid vulnerabilities specific to particular application domains (like CSS, SQL injection, etc...).
Also the OWASP top ten vulnerabilities: https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Proje...
http://www.cl.cam.ac.uk/~rja14/ http://www.cl.cam.ac.uk/~rja14/book.html
The original author sold the site in March before things got really serious.
for those who don't know
Man, these programmers are fucking amateurs. It's a FUCKING TRADING PLATFORM.
It happens everywhere.
http://www.federalreserve.gov/bankinforeg/reglisting.htm
Cause, I don't think they broke any rules. Are they even required to keep those details secret? It's pretty clear marketing agencies can buy that data, so i don't think it's any sort of violation of privacy policy.
...i hope
Guess what: Even salted hashes won't save your ass with such weak passwords. And yes: it's a FUCKING TRADING PLATFORM you want to put money on so _you_ should think of a secure password.