|
|
|
|
|
by sneeds
1608 days ago
|
|
> The site was created in 2006 with little knowledge of security, so passwords were stored in md5() hashes without salt
Sorry, but this is no excuse. It has been 15 years and there were so many breaches that even many casual people know about databases leaks and that passwords have to be stored in some special way. I don't know this guy's background, but he at least knows that md5 is not sufficient here. And then it never crossed his mind to do a check up on this? That's just negligent. |
|