Case 5F0E9F · Cryptography · L2 Practitioner
Password Dump Hits Pastebin
Practise as: Incident drill · Interview
Live alertA paste titled with your company name lists 1.2M emails with 32-hex-char hashes; a sample matches your legacy users table, which stores unsalted MD5.
Interview questionYour user password hashes have leaked and they are unsalted MD5. Walk me through the response.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Confirm authenticity by matching sample rows to production; identify the leak path (SQLi, backup, insider).
- Assume all passwords are cracked: MD5 runs at billions/sec on GPUs; force resets and revoke sessions and tokens.
- Migrate to Argon2id immediately (wrap MD5 hashes in Argon2id, then rehash on login).
- Notify users and regulators per law (e.g. GDPR 72h); warn about credential stuffing on other sites.
- Push MFA, add breached-password checks, and rate-limit logins to blunt stuffing waves.
If the interviewer pushes back
- Why is wrapping MD5 inside Argon2id acceptable as an interim step, and what are its weaknesses?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.