> The site was created in 2006 with little knowledge of security, so passwords were stored in md5() hashes without salt
Ouch!
I hope they learned their lesson: Security is an ongoing effort.
Ouch!
I hope they learned their lesson: Security is an ongoing effort.
To be fair to them it took till around 2008 for this to become widespread opinion but the signs were on the wall around 2004
When I joined my first company in 2010, to my horror, they were using plain text passwords for users