| ▲ | dredmorbius 17 hours ago | |
Poor password practice and policy, and likely a lack of 2FA / physical token security, seem to have contributed to this breach. Posts and screenshots apparently by the alleged attacker show "P@ssw0rd" and other well-known / readily-guessable passwords from the hacked systems: <https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...> <https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...> Originally noted, without references, by ExoticPearTree here: <https://news.ycombinator.com/item?id=48978836>. NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance. | ||
| ▲ | hinkley 16 hours ago | parent [-] | |
For me the first 2FA devices I’d had were for work but for my friends it was for a world of Warcraft. And it was years until my bank offered 2FA. I still think about that every time there is a breach. Blizzard gave hardware tokens out to the entire convention one year. Smart phones became a variable not long after and then they didn’t make them mandatory but game guilds almost universally did. Especially for officers. | ||