Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Insecure Password Hashing #97

Open
Danlock opened this issue Jul 10, 2017 · 0 comments
Open

Insecure Password Hashing #97

Danlock opened this issue Jul 10, 2017 · 0 comments

Comments

@Danlock
Copy link

Danlock commented Jul 10, 2017

I noticed that you are storing your passwords in the database unsalted using just an MD5 hash.
Here is why that's a bad idea.
https://security.stackexchange.com/questions/52461/how-weak-is-md5-as-a-password-hashing-function
https://security.stackexchange.com/questions/19906/is-md5-considered-insecure

Alternatives like argon2 or bcrypt are much safer.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant