55
you are viewing a single comment's thread
view the rest of the comments
[-] neo@lemmy.comfysnug.space 35 points 7 months ago

For context, this guy has a history of being dismissive of legitimate security concerns like using unsalted md5 passwords

[-] lemann@lemmy.one 3 points 7 months ago

Yikes, that is embarassing.

Is opencart written in PHP? Bcrypt has been a thing for decades now, and is literally a drop in replacement that handles salting et al. If the developer was hesitant to implement that, I'd rather go use Magento or shudder Shopify

[-] Zikeji@programming.dev 2 points 7 months ago

One of the first things I did when I took over an old php project was convert to bcrypt and add logic to automatically upgrade the hash on their next login (and in case you're wondering, we also removed the old insurance hashes and the upgrade logic after a while, forcing remaining users to do a password reset).

this post was submitted on 25 Nov 2023
55 points (96.6% liked)

Technology

33579 readers
224 users here now

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

founded 5 years ago
MODERATORS