3 ms·
> Because security is actually really hard, contrary to popular opinion. But some of the password hashing algos used, no salting, making all password character
by ssharp 10y ago
> Because security is actually really hard, contrary to popular opinion.
But some of the password hashing algos used, no salting, making all password characters lower-case in the background, etc. are not hard things to avoid. So when a site is hacked and the user information stolen and we find that stuff out, it's safer to assume other security practices where also subpar.
- iLoch 10y agoYup there are just a lot of bad developers out there, quite honestly.
- dvhh 10y agoAdd "cheap" to their traits, and it would help figure out why anybody would ask them to code anything
- ssharp 10y agoFor big sites, I have a hard time blaming it on a bad developer. Early in my career, I worked for a company that stored it's passwords in plain-text. I suggested on many occasions stop doing this and was always told no because the site had an older audience and they wanted to make it easy to send password reminders, which also meant they were emailing passwords in plain-text. This came from the tech director and CEO and none of the other devs seemed to care. A few years after I left, their DB was compromised, so someone got a list of email addresses with clear text passwords.