3 ms·
newly created passwords remain invulnerable to a similar disclosure, as they employ SHA-512 with per-user salts to store hashes. I don't know how long it will
by Xk 16y ago
newly created passwords remain invulnerable to a similar disclosure, as they employ SHA-512 with per-user salts to store hashes.
I don't know how long it will take for people to figure this out. SHA-512 with a salt is not the right way to store passwords. Yes, it's better by leaps and bounds than storing the plaintext. Yes, it's better than crypt(3) as gawker used. But come on, just use bcrypt already.
And the fact that they calls SHA-512 with salts "invulnerable" ... I don't even know what to say to that.
- csytan 16y agoI don't think a developer working at Mozilla would be so careless that they would use "invulnerable" to describe their security. Seems like it was an interpretation by the tgdaily author. Here's a link to the original blog post: http://blog.mozilla.com/security/2010/12/27/addons-mozilla-org-disclosure/ http://blog.mozilla.com/security/2010/12/27/addons-mozilla-o...
- Xk 16y agoYeah, my "they" was really unclear. I'm sure that no developer in his or her right mind would ever call anything "invulnerable." That's just asking for it. I guess it makes sense that the media would call something like that invulnerable though, they don't know anything about it anyways.