3 ms·
"The passwords appear encrypted so there is little threat that others can abuse this account information." This is nonsense, of course. Several of the hashes a
by robtoo 15y ago
"The passwords appear encrypted so there is little threat that others can abuse this account information."
This is nonsense, of course. Several of the hashes are googleable.
Sometimes I feel like web app security is still where unix security was 30 years ago. Before /etc/shadow.
(edit: and before setuid programs realised they should do privileged operations early then drop privs asap.)
Also, pastebin link because it's not included in the article: http://pastebin.com/tkmZDG9m http://pastebin.com/tkmZDG9m
- yuhong 15y agoThere are already good password hash algorithms available, like bcrypt. In particular, the problem of googleable hashes were solved long ago with salt. It is just that not all websites use them. To make things worse, it is hard to determine which password hash algorithm a site uses without having access to the source code.
- robtoo 15y agoThe solution to a fundamentally-flawed security architecture is not a better hash algorithm, sorry. bcrypt is good at what it does, but that is such a limited domain that it is insignificant next to the decades of security research and experience that many popular modern web apps blindly ignore. What does bcrypt have to do with the principle of least privilege, for example?