301
pesaply
4y

Forget your md5 or else

Comments
  • 8
    No! Just no! Sorry will not fix the fact he saved them in clear text. He deserves it 😒
  • 10
    The gun looks.. Wrong.

    Also, I'm not gonna comment on the "posture arrow" on their backs..

    Clear text passwords, eh.

    They should aim lower and shoot upwards for maximum pain before death occurs.
  • 9
    Plain text: Death sentence.
    Unsalted Hash: Chop off a hand.
    Hash with global salt (pepper): Ten lashes from the whip.

    Always use both pepper and salt with your hashes! 😁
  • 1
    @bittersweet i ruined you 8888 :) oh and ofc double salted sha
  • 2
    @Salmakis A little bit of sriracha, maybe some parsley... roast your hashes until they're a dark golden brown. Security is not that hard.
  • 0
    Why is his first suggestion 'memory leak'? Are those really death sentenceable?
  • 2
    My comp stores passwords in md5, don't even bother to salt and they have no idea how to access the backend to fix this shit.

    And I'm sitting there feeling like caressing a switch to eviscerate the company. Sigh...
  • 6
    Why salt passwords when you can pour honey in them? đŸ¯đŸ¯đŸ¯đŸ˜‹
  • 0
    A friend told me that a hungarian public transport company (called BKK - Budapest Transport Center or sg.) used plain text to store users passwords. Show'd me this repo, in which some hungarians created a library for BKK's hashing method in several languages.

    https://github.com/moszinet/...

    Edit: typo
  • 1
    @bittersweet I always burn my hash ☚ī¸
  • 0
    I came across this today in one of our internal apps...

    I wish I had a firing squad to hand.
  • 1
    @usethedocsluk you are correct. Source: I'm Hungarian.
    There also was an exploit where you could buy tickets for 1 Huf.
    The company sued the kid who discovered and reported it immediately.
  • 0
    md5 or bcrypt?
  • 0
    @DjSall wow. I hope the kids won the case.
  • 0
    @iguana it was covered up by the government. No one knows.
Add Comment