• ShadowA
    link
    fedilink
    English
    arrow-up
    34
    ·
    edit-2
    11 months ago

    In a post, the security firm said the username and “ridiculously weak” password were harvested by information-stealing malware that had been installed on an Orange computer since September.

    So the password being weak was actually irrelevant here, even if it was 32 random characters they would have pulled it off that pc.

    • cley_faye@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      11 months ago

      Depending on the attack vector it could also have pulled it out of other things, but that’s exactly why we have 2FA. And I mean real 2FA, on two different channels, that should be harder to compromise simultaneously.