15 karma · joined September 2, 2009
Bull.
Back in real life:...
Well, in my real life, I've never "rainbowed" a table, or even know what that is after 12 years in IT, but I sure can open a sql file in a text editor and figure out which field is the password.
It's a layer of defense and widely accepted as the minimum and so easy to implement it's ridiculous to argue against it, especially as a "movie plot threat".
Quick, somebody make a movie out of this:
1) That database dump of the users table that someone put on a usb drive and lost.
2) A brute-force attack via a misconfiguration which allows remote logins to mysql. No "rails stack" access, but the passwords are now compromised.
3) The non-application backup server with DB dumps.
4) S3 access is compromised and unencrypted dumps to S3 are downloaded.
I guess I could keep going, with the attacks getting more outrageous, but I can assure you that stranger things have happened.
Hyperbole may sell, but we don’t want to sell it.
Well, you sold it for a long time.
The clear text passwords thing is incomprehensible. These guys have move knowledge about rails in their toe jam than 99% of the "rails experts" out there and they can't implement hashed/salted passwords? Come on. How is this not a show stopper?