"The API was developed 9 years ago, and appears not to have been updated since."
Last.fm could have updated this, except it would have meant making all their users do something.
Last.fm could have updated this, except it would have meant making all their users do something.
BCRYPT(MD5(Password))
Running BCrypt or SCrypt over the current MD5 hashes is easy, and they can do it right now for every password. If someone (else) grabs the database in ten days time they get no MD5 hashes of passwords instead of half of the userbase.They send a token hashed with the password and they have to keep the original md5'd password on file in order to allow these clients to work.