5 ms·
> Auth providers cant help you because the passwords are hashed... You need the same algo or you cant authenticate using the data they have. You absolutely can
by MikeKusold 5y ago
> Auth providers cant help you because the passwords are hashed... You need the same algo or you cant authenticate using the data they have.
You absolutely can migrate away from Auth providers. Auth0 (disclaimer: former employer) hashes passwords with Bcrypt, which is most likely the same exact algorithm you would choose. Bcrypt stores salts & rounds as part of the hash making those hashes fairly portable.
Even if you wanted to change algorithms, there are ways to do this so that it is transparent to the user, such as running the plaintext password through a new algorithm after a successful authentication and storing it in a new column.
- mypalmike 5y agoHe mentioned transparent migration and the problems encountered with it.
- BoorishBears 5y ago> Auth providers cant help you because the passwords are hashed... You need the same algo or you cant authenticate using the data they have. Seeing as you have that it becomes a non-issue