3 ms·
I don't know enough about server security to critique most of that guide, but the Password Security section is clearly behind the times: > Passwords should alw
by kderbe 10y ago
I don't know enough about server security to critique most of that guide, but the Password Security section is clearly behind the times:
> Passwords should always be hashed using a strong, one-way hash algorithm. [...] hashed with an algorithm like SHA-256 7 times.
If they had simply written "just use bcrypt" they'd be much closer to 2016-era security practices.
- brokenwren 10y agoBCrypt works fine, but I wouldn't say it is "2016-era security practices". It was written in 1999 and hasn't had as much scrutiny as SHA or Blowfish (although it is based on Blowfish). Regardless, using a salted, multi-pass algorithm will keep everything nicely secured using nearly any hashing algorithm. Remember the goal is not to crack one user's password using a brute force lookup table, it is to crack everyone's password.