-10 karma · joined October 4, 2010
> My trivial point was that your claim about the down votes was contradicted in the first sentences. It seems you missed that, too.
I am sorry you think your thoughts are trivial and despite your grammatical errors I would love to know how a first sentence can be plural. I have no doubt that I missed a lot things prior. That was my entire point of my following posts. Maybe if I knew which first sentence you were referring to I could have a better response.
> Quite fun to do personal attacks like that after such creative way of misreading.
There were no personal attacks in the previous posts unless of course you are Perl. In this post maybe there are many only because you made it so.
And I would appreciate if you read this small thread, moderator, and came back with an intelligent reply.
Yes I could have not been a dick on this but you reap what you sow.
Edit: Thank you for trolling moderator.
I honestly have no idea what you mean by that :).
> Are you really surprised about the down votes...?
For that post of course not. For the others yes.
I can only assume you are coming from this viewpoint
"Please avoid introducing classic flamewar topics unless you have something genuinely new to say about them."
and no I don't think I had anything genuinely new to bring but I how could I know about something I didn't know about.
I guess what I am really saying if people can't acknowledge the flaws in a thing how could they ever make it better. And to say even more if they can't vocalize their reasoning how does downvoting make it okay but I am sure that is another thing I have missed.
EDIT: My original comment was really just meant to be humorous I am sure know why since you are aware of Perl's syntax. It did make me a lot of money at a time but nevertheless I stand by what I said as that is the best advice I could give myself right now.
Regards,
And FYI pypi is better than CPAN so all the other stuff in the that post is crap imho. I was a Perl dev for ~10 years. Now have about 5 worth of Python. So thank you.
I don't understand how generation numbers are derived information. They are used to find the position of the commit in relation to another. That makes them information that is essential to the commit. The problem was to get around them not being there timestamps were compared and that is not reliable for obvious reasons. So I really don't understand why any one would complain about this.
Please tell me where this multiplier comes from? If money was multiplied through taxes the USSR would still be around and booming as they had an effective tax rate of 100%. So do tell please.
I know I am getting totally destroyed here by the down voting and I'll probably end up in negative karma for this but I standby all of it.
I guess what I am really trying to say is that the state of web/Internet security is very poor right now and I don't believe bcrypt is worthy pursuit (sorry I am really not trying to troll). Since Mt.Gox was just hacked my salted password is on pastebin and then someone attempted to break into my gmail account but that will never happen because I use two factor authentication.
Maybe that is the best solution to all of this.
Yes I hope there are.
> I disagree. I think most people use SHA-1 because they know better than to store plaintext passwords. What they don't know is that it's terribly broken.
SHA-1 is the default on django and its easy to break that my entire point. It leaves a false sense of security.
> There are two problems here. (1) If you have access to the site's password database, there's a really good chance you have access to the entire database, and can look up how they're doing it. (2) Even if you can't lookup how they're doing it, you just try them all and find which one it is. I'd bet you money that if someone's hashing passwords, they're using one of {MD4, MD5, SHA0, SHA1, SHA2, DES}. If, god forbid, they're not using one of those and actually wrote their own hashing algorithm, you have even more to worry about.
They might as well be using ROT-13 if they are using any of those. Now with todays GPUs and rainbow tables the passwords might as well be in plaintext. The real solution is site security not password security.
> Or, you know, you could use bcrypt and be secure about it.
For how long? 4-5 years? Who will be maintaining your site then?