While I agree it's possible that the attackers also got this information but I don't think we can jump to conclusions about the overall security of the passwords until more information is known.
While I agree it's possible that the attackers also got this information but I don't think we can jump to conclusions about the overall security of the passwords until more information is known.
Password entries are generated as follows:
<salt> = random()
x = SHA(<salt> | SHA(<username> | ":" | <raw password>))
<password verifier> = v = g^x % N
G = 47
N = 112624315653284427036559548610503669920632123929604336254260115573677366691719
What was stolen was no better than LinkedIn hashes -- for the purposes of dictionary attacking the databaseMaybe you can look here: http://en.wikipedia.org/wiki/Modular_exponentiation.
Ok, I'll save you the trouble -- the modular exponentiation is O(log exponent). That's log as in... FAST.
Constants matter.
(Also, computational complexity of crypto algorithms is usually specified in terms of nbits, not numeric magnitude)
(Although this argument has given me an idea for everyone that thinks using the same password on different sites is reasonable - a browser extension that runs a client-side KDF :P)