[wp-trac] Re: [WordPress Trac] #2394: Passwords are stored in an insecure un-salted form

WordPress Trac wp-trac at lists.automattic.com
Fri Jun 29 13:34:57 GMT 2007


#2394: Passwords are stored in an insecure un-salted form
-----------------------+----------------------------------------------------
 Reporter:  sjmurdoch  |        Owner:  pishmishy   
     Type:  defect     |       Status:  assigned    
 Priority:  normal     |    Milestone:  2.4 (future)
Component:  Security   |      Version:  2.0         
 Severity:  normal     |   Resolution:              
 Keywords:  has-patch  |  
-----------------------+----------------------------------------------------
Comment (by Otto42):

 Replying to [comment:14 pishmishy]:
 > If we decide that there are faster ways to generate an md5 hash than
 through md5() then would it not make sense to make the change across the
 code and not just where it's involved with passwords?

 OOOOHHHHHHH! Okay. Sorry, you had me completely confused at first. Your
 original sentence structure was very weird, I thought you were saying that
 it used something other than MD5 for passwords somewhere.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/2394#comment:15>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list