Kommentare

Serendipity Snapshot: New login hashing

Simone am um :

I agree. If you're going to change, you might want to skip what's already considered unsecure. See http://www.schneier.com/blog/archives/2005/02/sha1_broken.html

Anonym am um :

read your link and try to understand... when salted, md5 and sha1 are both secure if used for passwords.

Garvin am um :

anonym,

additionally to what Anonym wrote (that using salted passwords is quite secure on its own already), we cannot easily use any SHA2-type algorithm because it's not contained in vanilla PHP distros. Emulating it in PHP-Scope would be both slow and a risk in implementation.

Simone am um :

hm... are you sure?

http://www.neurofuzz.com/modules/software/ssha_attack.php

Simone am um :

hm, the previous link actually talks about brute-forcing, so that may not be so useful after all... sorry :-)

Free Books am um :

Serendipity has always been had high tributes to backwards compatibility and ease-of-use and ease-of-upgrading, we have decided to take the "soft" upgrade approach. That means, new Serendipity versions will accept your old MD5 login ONCE, and then will use your user-specified password to create the safer hash and store that to the database.