- Joined
- Nov 4, 2017
Long passwords don't really help when goons tend to use the same names everywhere, so you could cross-reference other compromised sites and guess that a lot of them might just use the same password everywhere, and their SA one is just their usual password twice in a row. The ones that use Lastpass, proper unique passphrases, or somehow memorize a crazy password will be safe, but that can't be more than like one in every 10 or so accounts. Fuck's sake, I'll bet a hundred fucking dollars that if at least 500 passwords get leaked, there will be at least one social security number in there.
Long passwords are very hard to brute force, and are often not reused because you aren't going to use a 20-character password on another site if you don't have to. OTOH its also not very likely passwords need to be changed regularly.
This is not saying SA posters or Mods are smart people, just that SA seems to be competently architected because it hasn't been striaght pwned. Its not a walk in the park to take it over because their hacky phpBB code doesn't need a lot of open ports or infrastructure, so you can coat it in 24-inch firewalls.
Now, if you could get inside those firewalls, then yes, you probably would have a very exploitable chewy center you could just let Hackamania run wild on. But someone seems to have a good job at securing the borders.