Why do you switch to sha1, knowing this is already under attack similar to md5?
While it may take some time till sha1-attacks reach a state where this will matter for password storage, it'd be a safety measure to switch to sha256 with salt.
Garvin am um :
It's salted, so we could've even stuck to md5.
mike johnston am um :
Is there any eta on a release candidate or new beta?
Garvin am um :
Thanks for that bugreport. Sadly this was caused by a last minute change.
Please download this file:
http://svn.berlios.de/viewcvs/checkout/serendipity/trunk/include/functions_entries.inc.php
and overwrite the include/functions_entries.inc.php file with that.
Bectrade am um :
Thanks for your quick reply and fix.
Hanno am um :
Why do you switch to sha1, knowing this is already under attack similar to md5? While it may take some time till sha1-attacks reach a state where this will matter for password storage, it'd be a safety measure to switch to sha256 with salt.
Garvin am um :
It's salted, so we could've even stuck to md5.
mike johnston am um :
Is there any eta on a release candidate or new beta?
Garvin am um :
Yes, as soon as our SMTP is up again, the release will be posted.