Are they saying the passwords were hashed with MD5 before January? Because that'd be a bit scary.
Are they saying the passwords were hashed with MD5 before January? Because that'd be a bit scary.
Also I still see people now and then arguing that salted md5 is perfectly secure and that using a slower hash or any hash at all either doesn't add value or actually harms value. So they may not know better, or they may know better and simply not care.
Do you have evidence to support this?
I wouldn't say that security is considered a waste of time.
It is, however is a trade-off[1] between money, time, and other resources, things that, generally speaking, start-ups tend to be short on.
I worked for a startup that provided multifactor authentication using biometrics (amongst others), and almost all of our business came after publicized (and not publicized) breaches, from both large and small firms.
Maybe my comment was a bit too biased and hyperbolic, but I've certainly encountered that attitude.
Actually, a browser add-on to load commentary/annotations for known tutorials on the fly might be nice. All sorts of practical problems that would have to be overcome, though (like changing content and getting people to use the add-on in the first place).
Poke around w3schools. That should give you more than enough initial grist for your mill.
I'm hoping that all they've done is use bcrypt(salt, HMAC-SHA256(salt, pw)) to get around the bcrypt 72 character limit. However, using scrypt would have been better.
Intuitively it seems like you'd still need to guess the bcrypt portion, making it no worse than just bcrypt.