3 ms·
> Gawker saved passwords. You should never, ever store user passwords. If you do, you're storing passwords incorrectly. Always store the salted hash of the pass
by Xk 16y ago
> Gawker saved passwords. You should never, ever store user passwords. If you do, you're storing passwords incorrectly. Always store the salted hash of the password -- never the password itself!
Uh, no? They did save the hashed+salted version. The only problem is that they used crypt, from 20 years ago, instead of something like bcrypt.
- starting_over 16y agoAre you sure it was salted? john the ripper took all of 24 minutes to crack my password.
- Xk 16y agoYeah, I am. I'm looking at the database right now. I would assume they had more, faster computers. And the passwords they broke were only the simple ones -- I would assume your password is not password1.