Answer the question
In order to leave comments, you need to log in
How did Instagram know that my password was compromised on another site?
Recently, my email account on the hosting was maliciously exploited for sending spam. As it turned out later, the attacker found my password somewhere and connected directly to SMTP. Changing the password didn't help because it didn't work. Everything was fixed. Changed passwords. I broke my head - where could I burn my password. Unless some site was hacked and all the passwords leaked to the network, including mine.
And today I received a notification from my Instagram that my password matches the one that was recently stolen on another site and that they say I need to change it. So the question is: how did they know about it?
Answer the question
In order to leave comments, you need to log in
Да лаадно.
1) Имем где-то базу паролей с мылами.
2) Знаем (мы же инстаграм!) алгоритм генерации хэша
3) Генерируем хэш из слитого пароля
4) Проверяем с хэшем в базе
5) Если совпало - бьём тревогу.
Отсюда вопрос: откуда они об этом узнали?В крупных компаниях за этим делом следят.
АртемЪ: Теория на мой взгляд верная, но это возможно только если, как мы все уже поняли: либо инстаграму досталась база утекших паролей в открытом виде, либо инстаграм хранит пароли в открытом виде, либо алгоритм хранения паролей инстаграм совпал до соли с алгоритмом загадочного сайта.
Если понадеяться на благонадежность фейсбука, то вероятнее всего первый сценарий. Тогда любопытно на каком ресурсе есть такая база.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question