The token is a password equivalent, and should thus not be stored in clear (use scrypt or a similar scheme).
The token is a password equivalent, and should thus not be stored in clear (use scrypt or a similar scheme).
I've tested many many many many applications in the last X years and not one of them has ever done this, nor would I ever recommend that they do it.
Probably, yeah...
In the case they only have read access to the token DB, and need write access, or read access to another part of the system, it becomes an attack vector.
It is not a cargo-cult measure, and it doesn't add much complexity (just re-use your password encoding logic).
The same goes for session tokens, BTW.
> [...] nor would I ever recommend that they do it.
Maybe you should reconsider that. I know who you are, and how knowledgeable and experienced you are, but in this case I think you're just wrong.
A cargo cult is not an argument.
I would not hash reset tokens, but I didn't downmod you for suggesting it. I would get mad at you if you worked on my team and dinged a client for not doing it, though. :)
And now you're begging the question!
Actually, some people use it :-).
It shuts down an attack vector, and it's cheap to implement. Why is it silly? My rule of thumb is to treat all passwords equivalents in the same way.
I'm honestly surprised by your hostility towards the idea (not mine, BTW), and by the downvotes for promoting a strategy that provably (in the math sense) increases security.
http://stackoverflow.com/questions/549/the-definitive-guide-...
Edit: Even if it were just me, it doesn't make the argument invalid.
Your arguments so far are
1) it's unlikely to be the weakest link. Textbook case of Murphy's law,
2) nobody does it, and
3) I've never recommended it, therefore it's useless.
I don't understand how you can resort to that... Seriously, I'm at loss here. Are you waiting for a high profile attack to react?
I know you have a reputation to defend, but I think you screwed it somehow in this case.
At least, it proves you're not a machine :-)
:)
Edit: random Divine Comedy song: http://www.youtube.com/watch?v=EN65hsrtg94