- Joined
- Jul 4, 2022
Actually, I'm inclined to believe him on this one. You'd have to go out of your way to store MW passwords in plaintext, and password reuse is really a widespread security problem. The password list that was posted here was also a lot smaller than the entire userbase. And if I remember right, most passwords were weak.You totally didn’t choose to store all your users’ passwords in plaintext (which isn’t the default for Mediawiki)
So them being from a leaked password database that was then cracked offline is more plausible. Someone posted a screenshot of the ban page saying "BASED INDIVIDUALS", which made me consider whether it had in fact been breached, but that's trivial to do with Inspect Element.
That said, it's an actually interesting line of thought whether it constitutes a breach from the GDPR's standpoint if your users are retarded and they get their passwords stolen without the site having been touched.