3 ms·
8 digits password... It sound like DES encryption stored directly in the database. (This is pure speculation of course) This alone is a huge red flag. Adding t
by Flott 12y ago
8 digits password...
It sound like DES encryption stored directly in the database. (This is pure speculation of course)
This alone is a huge red flag. Adding the fact that the 2 factor auth. is broken is not a good news.
- psykovsky 12y agoHow about the case insensitivity on the passwords? How does that fit with DES encryption, or any kind of encryption at all?
- MichaelGG 12y agoUser friendliness. FB did something similar where they'd store several versions of your password. That way they could tell if you had caps lock on or other problems.
- psykovsky 12y agoYou really used facebook as a best practices example? Where is the source code of facebook's function that deals with case insensitive passwords? How can you be sure such source code is actually being used in production? It's as good as plaintext without any of those assurances...
- ryan-c 12y agoI think you mean DES based crypt and not DES encryption.
- Flott 12y agoYes that's what I meant, thanks.