3 ms·
It should be criminal.
by kokowawa393 7y ago
It should be criminal.
- alasdair_ 7y agoPeople that re-use passwords should be considered negligent. There is no reason to do so for anything but the most trivial logins.
- gruez 7y agoGood luck proving that a "reasonable person" shouldn't have done it. Most people on HN probably do, but I wouldn't be surprised if everyone coming out of a 3 month coding bootcamp only knew to hash passwords and nothing else. The other comments in this thread seems to suggest that the company is filled with bootcamp programmers.
- shakna 7y agoAs a government body actually publishes advice on this, NIST [0], it may well be possible to argue for what is reasonable in a court of law. [0] https://csrc.nist.gov/projects/hash-functions/nist-policy-on-hash-functions https://csrc.nist.gov/projects/hash-functions/nist-policy-on...
- adrr 7y agoI just googled how to store passwords in a DB and the first result said I shouldn’t use MD5 or SHA. Reasonable person would do a cursory search for information if they didn’t have the knowledge. I am willing to bet they knew better. When I worked for a company that stored passwords in clear text, we knew it was wrong but never prioritized fixing it. If the execs would have faced jail time, I bet it would have been prioritized.