Comment by dredmorbius
18 hours ago
Poor password practice and policy, and likely a lack of 2FA / physical token security, seem to have contributed to this breach.
Posts and screenshots apparently by the alleged attacker show "P@ssw0rd" and other well-known / readily-guessable passwords from the hacked systems:
<https://news.ycombinator.com/item?id=48978836>.
NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance.
For me the first 2FA devices I’d had were for work but for my friends it was for a world of Warcraft. And it was years until my bank offered 2FA. I still think about that every time there is a breach.
Blizzard gave hardware tokens out to the entire convention one year. Smart phones became a variable not long after and then they didn’t make them mandatory but game guilds almost universally did. Especially for officers.