4 ms·
Oh man oh man.... This hurts just reading that, or UPDATE without WHERE.
by markatkinson 11y ago
Oh man oh man.... This hurts just reading that, or UPDATE without WHERE.
- odinduty 11y agoI have a story about that based on real facts(TM): I once had to reset my own password on a production database and I decided to hash it by hand and UPDATE my row in the users table. A few hours later we had got a few calls from angry customers who couldn't log in. I had effectively forgotten the WHERE clause so all users had the same password: mine. Extra points for not having read the "xxx rows updated" line that the mysql console outputs after each query...
- Gigablah 11y agoTechnically they didn't have the same password, unless you're saying that your passwords aren't salted ;)
- odinduty 11y agoI updated the hash and the salt in the same query. They weren't salted against the user id or anything like that, just a second column for the salt, which is... common practice.
- jsjohnst 11y agowhere do you get that conclusion? There's a lot of ways the password could be literally the exact same string, yet still be salted and even peppered.
- mpnordland 11y agoI like adding garlic to my passwords, gives them a kick!
- jsjohnst 11y agoYour response could be taken as a joke (made me laugh anyway!), but also seriously too. If it was serious, what do you use as garlic and why?
- mpnordland 11y agoIt was a joke, I'm not sure what garlic would be added to a password.