logoalt Hacker News

IceDane • today at 1:19 PM • 1 reply • view on HN

Why would you think active directory has anything to do with this? That seems like a super random conclusion.

What happened is they found the password and email for an employee in a dump online - possibly for a different service, we don't know. If so, then the password was reused.


Replies

saghm • today at 1:40 PM

I mostly agree with you, but it's worth considering that there are much more fundamental issues with absolutely abysmal passwords like "123456" . If my password is "ra1nbowC0okies776", and it shows up in another place, it's a pretty strong signal that I reused it, because it's unlikely to have been picked independently by someone else. If my password is "password", even if I never reuse it, that's still far worse than me reusing the password above.

➕ show 1 reply