Life, Photography, and Security

Random thoughts that have crossed my mind

Thoughts on...

October
Mon Tue Wed Thu Fri Sat Sun
       

Subscribe
Subscribe to the RSS feed.

2007-10-15

Nincompoops!

Recently, a list of 78+k password hashes to various Finnish internet forums was posted on the net. Apparently a number of bulletin boards were hacked, and the password hashes extracted. Some passwords were actually plaintext, suggesting that some software even stores passwords in plaintext.

The most striking aspect of the list, however, is the fact that a huge portion of the password hashes are not using salts. That is just plain depressing. How to properly compute and store password hashes has been know for decades, but still incompetent programmers keep repeating the errors of history.

There is a lovely English word for the programmers who have omitted to use proper password encoding methods in their forum software. “Nincompoops”. You know who you are. Shame on you!

[/security] permanent link