I agree. If you're going to change, you might want to skip what's already considered unsecure. See http://www.schneier.com/blog/archives/2005/02/sha1_broken.html
Anonym am um :
read your link and try to understand...
when salted, md5 and sha1 are both secure if used for passwords.
additionally to what Anonym wrote (that using salted passwords is quite secure on its own already), we cannot easily use any SHA2-type algorithm because it's not contained in vanilla PHP distros. Emulating it in PHP-Scope would be both slow and a risk in implementation.
Serendipity has always been had high tributes to backwards compatibility and ease-of-use and ease-of-upgrading, we have decided to take the "soft" upgrade approach. That means, new Serendipity versions will accept your old MD5 login ONCE, and then will use your user-specified password to create the safer hash and store that to the database.
Simone am um :
I agree. If you're going to change, you might want to skip what's already considered unsecure. See http://www.schneier.com/blog/archives/2005/02/sha1_broken.html
Anonym am um :
read your link and try to understand... when salted, md5 and sha1 are both secure if used for passwords.
Garvin am um :
anonym,
additionally to what Anonym wrote (that using salted passwords is quite secure on its own already), we cannot easily use any SHA2-type algorithm because it's not contained in vanilla PHP distros. Emulating it in PHP-Scope would be both slow and a risk in implementation.
Simone am um :
hm... are you sure?
http://www.neurofuzz.com/modules/software/ssha_attack.php
Simone am um :
hm, the previous link actually talks about brute-forcing, so that may not be so useful after all... sorry :-)
Free Books am um :
Serendipity has always been had high tributes to backwards compatibility and ease-of-use and ease-of-upgrading, we have decided to take the "soft" upgrade approach. That means, new Serendipity versions will accept your old MD5 login ONCE, and then will use your user-specified password to create the safer hash and store that to the database.