I didn't say it was easy; it's usually pretty hard/expensive to do it right.
But there are known best practices, and it looks like those weren't followed (at the very least, have a good password policy and salt the goddammed passwords before hashing).
here are two examples of companies doing security right:
But there are known best practices, and it looks like those weren't followed (at the very least, have a good password policy and salt the goddammed passwords before hashing).
here are two examples of companies doing security right:
[1] http://blog.lastpass.com/2011/05/lastpass-security-notificat...
[2] http://arstechnica.com/gaming/news/2011/11/valve-confirms-st...