5 ms·
Here's an interesting tweet from one of their developers. http://twitter.com/ReinH/status/50348989366796288 http://twitter.com/ReinH/status/50348989366796288
by Popcorned23 16y ago
Here's an interesting tweet from one of their developers.
http://twitter.com/ReinH/status/50348989366796288 http://twitter.com/ReinH/status/50348989366796288
> Your password in the database is SHA512 encrypted, but we're not taking chances.
I hope he knows what he's talking about and is just tired from the past few days.
- 16s 16y agoLet's hope they are salted and iterated.
- jarin 16y agoOr swapped over to Bcrypt
- lyonheart 16y agowe've cleared the old SHA512-salted passwords out of our production database and have upgraded the password hashing to bcrypt, with a cost of 10.
- jarin 16y agoGood call :) Just in case anyone doesn't know why Bcrypt is so awesome, it's because it actually takes longer to hash (based on the difficulty level you set, and you can bump up the difficulty level as hardware gets more powerful). For other applications, you want hashing to be fast. But for passwords, you want hashing to be as slow as possible without compromising user experience.
- lyonheart 16y agoI wanted Lucas to link to Coda Hale's post on bcrypt (found by googling "Coda Hale bcrypt") in the blog post, but he edited that out. So it goes.