Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Gawker saved passwords. You should never, ever store user passwords. If you do, you're storing passwords incorrectly. Always store the salted hash of the password -- never the password itself!

Uh, no? They did save the hashed+salted version. The only problem is that they used crypt, from 20 years ago, instead of something like bcrypt.



Are you sure it was salted? john the ripper took all of 24 minutes to crack my password.


Yeah, I am. I'm looking at the database right now.

I would assume they had more, faster computers. And the passwords they broke were only the simple ones -- I would assume your password is not password1.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: