Skip to content

Comment on 9M Australians affected by Optus data breachparent

Comments

Why the hell were they storing it? just delete it after marking the account as verified.

Even if it needs to be verified afterwards, the numbers could be bcrypted with high enough iteration count to make them impossible to brute force but easy to verify every few years if necessary... Say 10sec per id?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.