|
|
| Problems? Is your data what you think it is? | |
| PerlMonks |
Re^4: Status of Recent User Information Leakby Anonymous Monk |
| on Aug 02, 2009 at 06:40 UTC ( [id://785198]=note: print w/replies, xml ) | Need Help?? |
|
Also, hashing the passwords does not make them that much safer. Are you talking md5/sha1 hmac stuff like the Linux shadow files? Well, a few hours with john will get you a huge majority of the passwords I imagine, even with salts. Absolutely, they had access to all the code base. Probably this was a bad design decision unique to this particular e2 site. I just checked, it is the default in the codebase. Maybe other sites wrote updates, but they haven't made it back to sourceforge.
In Section
Perl Monks Discussion
|
|
||||||||||||||||||||||||||||||