>Yeah I've seen some old accounts just started posting again today after years of not being used Sad.
How is this going to change above? The hacked accounts make it pretty clear that either the passwords weren't salted, or the hackers managed to do much more than garb a db of password hashes & emails. Theymos did say he was rooted :
You cannot assume Theymos is lying and the database wasn't salted. We don't know if the security question was encrypted and salted as well.
I'm assuming nothing. Merely laying out the possibilities, so that they could be eliminated, one by one. In other words, theymos is not lying, the passwords were salted, which leaves only one plausible explanation for shitloads of VIP accounts flooding online: The hackers got a lot more than password hashes & emails.
Any old accounts compromised likely used easy passwords or easy security questions.
VIP accounts in a forum that's all about privicy, security & crypto? You sure?
Forcing a password reset where the recovery must happen through email will protect all those accounts unless the user were ignorant enough to use the same password for their email account as here.
Protect all which accounts? The ones posting here now? Or the accounts on the db dumps? Those probably changed hands a few times by now.
You can still crack salted passwords you know.... you just can't use a rainbow table to speed up the process.