Open cardosec

Case 5F0E9F · Cryptography · L2 Practitioner

Password Dump Hits Pastebin

Practise as: Incident drill · Interview

Live alertA paste titled with your company name lists 1.2M emails with 32-hex-char hashes; a sample matches your legacy users table, which stores unsalted MD5.

Interview questionYour user password hashes have leaked and they are unsalted MD5. Walk me through the response.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Confirm authenticity by matching sample rows to production; identify the leak path (SQLi, backup, insider).
  2. Assume all passwords are cracked: MD5 runs at billions/sec on GPUs; force resets and revoke sessions and tokens.
  3. Migrate to Argon2id immediately (wrap MD5 hashes in Argon2id, then rehash on login).
  4. Notify users and regulators per law (e.g. GDPR 72h); warn about credential stuffing on other sites.
  5. Push MFA, add breached-password checks, and rate-limit logins to blunt stuffing waves.

If the interviewer pushes back

  • Why is wrapping MD5 inside Argon2id acceptable as an interim step, and what are its weaknesses?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.