Charlie_
Tester
Miss Blue said:CruxJ said:Bill said:Skypo said:I hold server management accountable and responsible for lacking serious security or pro-active protective measures for breaches like this.
Unacceptable.
Because if whoever did this can pull this off without too much effort apparently, anyone with some technical knowledge could have.
You should only blame people with weak passwords.
Data Protection Laws require the data holders, ie the people maintaining the database and so on responsible for making data as secure as possible. If the passwords were as secure as possible on the database side then sure, blame everybody else. But that wasn't the case, they were (apparently) using a simple hashing algorithm that can be cracked in milliseconds using online tools.
That, does not make sense at all.
This is a server on SA-MP; not a company that holds millions of information.
Fr0st does everything possible to secure this information to the best of their abilities, and i'd shoot myself in the head if he didn't.
"This is a server on SA-MP; not a company that holds millions of information." - They're holding sensitive data. That doesn't make them exempt from securing it. People use their RC:RP passwords probably for most of their other accounts, the burden doesn't lie on the user - it lies on the person holding the data. It's common sense to anybody making any form of program/service that will be holding user data to make it secure as possible. It would've taken one small step to secure the passwords, using a random salting algorithm; that isn't rocket science.
Don't get me wrong, I don't see the point in arguing about it. But I think the point needs to be made so this mistake never happens again. Just because RC:RP isn't Microsoft doesn't mean they should be lenient with your or my data, it's a legal obligation to protect it.