Slow, crashed within minutes of using it. It's not very pretty either. I'll stick with Adium/Jabber hooks but was really hoping for something good here.
13 karma · joined January 10, 2011
What prevents the same enumerating attack against the sign up form. Are you going to give them a generic message that the username is invalid when it in fact has been taken?
Also the article implies that you need to use salt but than recommends using bcrypt which already includes salt.
Good read on how passwords are attacked.