Earlier quoted context omitted.
> Kim denied this. “We don’t use MD5 for our passwords to store them,” he said. “The MD5 keys were a log and it does not represent how we are managing data. We use more advanced methods like salted hash and SHA2 on securing users’ data in our database.” !!!!!!
While SSHA2 isnt that bad if they’ve applied a work factor, but that’s probably not the case.
At Blind, a security lapse revealed private complaints from tech employees
11–20 of 141 posts
Re: At Blind, a security lapse revealed private complaints from tech employees
#12Oh, and on the topic of security, one guy found a SQL injection exploit and demonstrated it by giving any users who commented on their post 100 likes...
Re: At Blind, a security lapse revealed private complaints from tech employees
#13Re: At Blind, a security lapse revealed private complaints from tech employees
#14People just trusted it?
I get that to seem legitimate the users have to be confirmed in some way, but as a user... now way am I exposing myself that way.
Re: At Blind, a security lapse revealed private complaints from tech employees
#15Earlier quoted context omitted.
While SSHA2 isnt that bad if they’ve applied a work factor, but that’s probably not the case.
It doesn't matter what algorithm you use to hash passwords when users login if you also store them md5-ed somewhere else!
;)
Re: At Blind, a security lapse revealed private complaints from tech employees
#16Re: At Blind, a security lapse revealed private complaints from tech employees
#17Re: At Blind, a security lapse revealed private complaints from tech employees
#18I'd never checked out Blind before. I just went there and checked out a few of the front page posts & comments. It has some of the most toxic and destructive "advice" I've seen for people asking for help or insight. I'm a bit astounded. Is this typical?