4 ms·
Does anyone know the origin of "usesomesillystri" as a salt? Googling that string found more results than I expected, but most of them are from password files w
by alexbock 10y ago
Does anyone know the origin of "usesomesillystri" as a salt? Googling that string found more results than I expected, but most of them are from password files with no explanation.
I found some PHP example code that tries to use "usesomesillystringforsalt" as a salt, is this just the aftermath of people writing real websites based on online examples? It seems a bit more pervasive in password dumps across the internet than I would expect unless it's in a really high profile example somewhere.
edit: It appears to be used in the official PHP documentation for crypt[0].
[0] http://php.net/manual/en/function.crypt.php http://php.net/manual/en/function.crypt.php
- jharger 10y agoI guess they missed this part of that example: /* These salts are examples only, and should not be used verbatim in your code. You should generate a distinct, correctly-formatted salt for each password. */
- deleted 10y ago[deleted]
- dogma1138 10y agoCopy paste. I had a fun exercise with a client that said they don't need a process to control the take in, audit and validation of 3rd party (mainly open source) code in their SDLC process because they strictly prohibit it in their coding policy. I ran a code plagiarism tool on the top 500 github repos and on some list of the top most common code questions from stackoverflow and found 1000's of hits on only a small part of their code base with even comments copied directly from stack being not to uncommon. In one particular instance it was a perfect storm of stupidity they had some code that was supposed to take user provided files and store them on S3 the example they copied from actually had a valid AWS access token of another company if that code was live the files which would be mainly their customers invoices and tax info could've ended up on some one else's server. After that afternoon I never had a single pushback from neither their head of development nor their compliance guys ever again.