Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. Don't know if you looked at this...

Don't know if you looked at this...

Scheduled Pinned Locked Moved The Lounge
htmlcomsecurityhelpquestion
6 Posts 4 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S Offline
    S Offline
    Soulus83
    wrote on last edited by
    #1

    ...but I just saw it and I think it was terrible :( Gawker Hack Release Notes Per the little sister rule I can't describe how I think they left these guys website...just remeber an image of some episode of L&O: SVU Problem is, god knows how many sites store passwords as plain text, and IIRC, DES encryption was used for some things (not user authentification at least) at my last employer systems... Dear hamsters, you don't do this type of storage do you? :(

    E A 2 Replies Last reply
    0
    • S Soulus83

      ...but I just saw it and I think it was terrible :( Gawker Hack Release Notes Per the little sister rule I can't describe how I think they left these guys website...just remeber an image of some episode of L&O: SVU Problem is, god knows how many sites store passwords as plain text, and IIRC, DES encryption was used for some things (not user authentification at least) at my last employer systems... Dear hamsters, you don't do this type of storage do you? :(

      E Offline
      E Offline
      Electron Shepherd
      wrote on last edited by
      #2

      Rosendo Lopez wrote:

      Dear hamsters, you don't do this type of storage do you?

      Well, CP offers an "email your password if you forget it" option, so the actual password, not just a hash, must be stored somewhere. Encrypted we hope, but still stored in a retrievable form.

      Server and Network Monitoring

      D 1 Reply Last reply
      0
      • S Soulus83

        ...but I just saw it and I think it was terrible :( Gawker Hack Release Notes Per the little sister rule I can't describe how I think they left these guys website...just remeber an image of some episode of L&O: SVU Problem is, god knows how many sites store passwords as plain text, and IIRC, DES encryption was used for some things (not user authentification at least) at my last employer systems... Dear hamsters, you don't do this type of storage do you? :(

        A Offline
        A Offline
        AspDotNetDev
        wrote on last edited by
        #3

        http://www.codinghorror.com/blog/2010/12/the-dirty-truth-about-web-passwords.html

        [WikiLeaks Cablegate Cables]

        S 1 Reply Last reply
        0
        • A AspDotNetDev

          http://www.codinghorror.com/blog/2010/12/the-dirty-truth-about-web-passwords.html

          [WikiLeaks Cablegate Cables]

          S Offline
          S Offline
          Soulus83
          wrote on last edited by
          #4

          Exactly where I got it! BTW, the xkcd cartoon is just too good :laugh:

          A 1 Reply Last reply
          0
          • S Soulus83

            Exactly where I got it! BTW, the xkcd cartoon is just too good :laugh:

            A Offline
            A Offline
            AspDotNetDev
            wrote on last edited by
            #5

            Rosendo Lopez wrote:

            Exactly where I got it!

            Yeah, I saw that your URL was from Coding Horror... just decided to post the link to the main article for everybody else. :)

            [WikiLeaks Cablegate Cables]

            1 Reply Last reply
            0
            • E Electron Shepherd

              Rosendo Lopez wrote:

              Dear hamsters, you don't do this type of storage do you?

              Well, CP offers an "email your password if you forget it" option, so the actual password, not just a hash, must be stored somewhere. Encrypted we hope, but still stored in a retrievable form.

              Server and Network Monitoring

              D Offline
              D Offline
              Dan Neely
              wrote on last edited by
              #6

              It's encrypted. I know Maunder talked about making retrieval a user togglable setting at one point (if no only a hash would be stored); but don't know if it was implemented.

              3x12=36 2x12=24 1x12=12 0x12=18

              1 Reply Last reply
              0
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Don't have an account? Register

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • World
              • Users
              • Groups