Storing passwords
Storing passwords
Posted Oct 12, 2011 12:08 UTC (Wed) by mordae (guest, #54701)In reply to: Storing passwords by bjartur
Parent article: WineHQ database compromised
Ah, there is also the "registration password is hashed in the same way" part missing in my post. Once we've sent password to the server unencrypted, it's not sane to assume it have been stored securely even if we authenticate through digests.