> Though I do understand it is a pain to migrate users over since you can only do it when they log in.
Had a thought on this, but I'm no security expert so if someone else could weigh in, that'd be awesome. Couldn't you just add a layer to the password hashing?
I.e., you start with MD5 because that's the best at the current point in history. Bcrypt comes around and you want to do a migration of all your users, so you take the stored MD5 hashes and run them through bcrpyt. Making sure, of course, that your login system does the same, MD5 followed by bcrypt. When the next-gen hashing algorithm comes around, you do the same, now the path is MD5->bcrypt->next-gen.
That way you're relying on the strongest algorithm "wrapping" the weaker one(s) without having to make everyone login again to generate the new hashes to be stored.
Curious to know if there are downsides to this (performance is an obvious one) or whether you're weakening the stronger hash by hashing a weaker one?