Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Two things missing from this statement that should be part of this note and every note like it:

1) How were the passwords stored (hashed? what algorithm? what parameters?)

2) How were the CC #'s stored (encrypted? what cipher/mode/etc?)



> Our evidence shows that only one Spotify user’s data has been accessed and this did not include any password, financial or payment information.


I think the point here is if your data has been breached you should be reassuring people that password and payment details even if accessed aren't easily readable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: