safer password storage
In the light of what happened on jan 19th when some retard found it could be funny to crack/hack dtoid and get all users passwords, I suggest that instead of storing actual passwords in the user database dtoid should store checksums
21
votes
All set! All passwords are now hashed, salted
1 comment
-
linuxguy
commented
as ainmosni suggests a salt should be used in conjunction with the hash