3 ms·
> members whose passwords have not been compromised benefit from the enhanced security we just recently put in place, which includes hashing and salting of our
by mjschultz 14y ago
> members whose passwords have not been compromised benefit from the enhanced security we just recently put in place, which includes hashing and salting of our current password databases.
If we presume that the 6.5m password dump was the past version, it shows that they just hashed the passwords before. This sentence (if I'm interpreting correctly), indicates that they were plaintext and were recently changed from plaintext to hash(salt+password).
I must be missing something in my interpretation though, because there isn't any evidence that they had the plaintext passwords to begin with.
(My assumption is that he means any user that has recently logged in was transparently moved to the hash(salt+password) scheme they are using now and previously just had hash(password) in place.)
- unreal37 14y agoI don't interpret that as meaning any passwords were stored as plaintext. The act of logging in caused them to create a new password hash that included a salt, which was stored in the database (and presumably wiped out the old one.) That all can be done without plaintext storage.
- mjschultz 14y agoRight, that's what my assumption is too but I didn't see anything in the post that says "recently logged in users" or "once you log in you'll be protected by the new scheme." Just "members whose passwords have not been compromised benefit [from the new scheme]".