4 ms·
Totally agree Coda gets the basics right and I love that article. In fact, our CTO wrote a response blog article to that in February: http://www.stormpath.com/b
by chunsaker 14y ago
Totally agree Coda gets the basics right and I love that article. In fact, our CTO wrote a response blog article to that in February: http://www.stormpath.com/blog/strong-password-hashing-apache-shiro http://www.stormpath.com/blog/strong-password-hashing-apache...
However, to quote from that post: "The author is correct assuming the attacker has direct access to your password store. This is a big assumption - most organizations go through great lengths to ensure access to say, databases, is levels of security 'deep' beyond just a web login form. Anyway, assuming that this might ever happen to you, how can you address the issue?"
- tptacek 14y agoIterated SHA2 is inferior to bcrypt and far inferior to scrypt, and yet both these Stormpath.com articles recommend it. The advice in these articles is worse that Coda's articles; developers should read Coda's post and implement it.
- chunsaker 14y agoYou're talking about Bcrypt like its some magical golden unicorn that will cover your ass from all attack vectors. Sure, its awesome. But modern security requires more than just an awesome encryption algorithm.
- asalazar 14y agoAssuming the attacker has access to your password store is NOT a big assumption for most sites. In fact, 94% of data breaches are to the user DB. And 42% of those attacks are targeting the password store specifically. Check out the Verizon Data Breach Report for details. http://bit.ly/GFfpdk http://bit.ly/GFfpdk