3 ms·
They could update hashes on login if needed. So i guess its something they don't want to talk about
by PolCPP 10y ago
They could update hashes on login if needed. So i guess its something they don't want to talk about
- matthewrudy 10y agoTrue point. That's normally how you'd do a hashing upgrade * decide an upgrade window * each time a user logs in check their hash version, upgrade if necessary * the upgrade period expires * if you can, force log out all non-upgraded users - hoping they'll now log in and get auto-upgraded * email all non-upgraded users and ask them to update their password Hopefully that set of users is now very small.