3 ms·
for 2006 that's actually not bad. When I joined my first company in 2010, to my horror, they were using plain text passwords for users
by ilogik 5y ago
for 2006 that's actually not bad.
When I joined my first company in 2010, to my horror, they were using plain text passwords for users
- labster 5y agoMy first company was using MySQL’s OLD_PASSWORD() function in 2013 — straight, with no salt or spice of any kind — in its 64-bit glory. Horrified, I did some research and threw bcrypt up there right away. Not sure if it was my my first commit, or the branch fixing 20 or so SQLIs was the first. I became my company’s software security expert out of sheer terror.
- BlueTemplar 5y agoYeah, just last month I was shocked to see a shop where I forgot my 2017 password, to send it to me. in plain text. by e-mail. (at least IIRC they used HTTPS on their website !)