• kate
    link
    fedilink
    English
    253 months ago

    obligatory bcrypt is not encryption

      • kate
        link
        fedilink
        English
        63 months ago

        this is true, and the name bcrypt can be misleading to non experts. i don’t blame them for getting this wrong in a pr statement 🤷‍♀️

    • Prison Mike
      link
      fedilink
      English
      33 months ago

      I don’t think I’d make that information public were I in their shoes. Wouldn’t that be a hint for anyone attempting to crack them?

      • kate
        link
        fedilink
        English
        53 months ago

        no, it’s (usually) stored as a part of the hash

        • Pika
          link
          fedilink
          English
          2
          edit-2
          3 months ago

          This is actually an optional thing, by default it will but it can be configured to be stripped, generally not a recommended thing though because it means that whenever you want to change the iteration count or the you need to force a password reset on every existing user

  • @[email protected]
    link
    fedilink
    English
    8
    edit-2
    3 months ago

    Pretty good disclosure text. There are much bigger companies that don’t manage to be this clear.

    The only nitpick I have is saying “encypted” with bcrypt, even though they clearly know that bcrypt only hashes things.

    • Pika
      link
      fedilink
      English
      53 months ago

      I’m willing to give him a pass on that one since they’re probably worried that their General audience will understand the word encrypted but not understand the word hashed

  • Kokesh
    link
    English
    53 months ago

    What the hell is Club Penguin?

      • @[email protected]
        link
        fedilink
        English
        63 months ago

        Hey, I was born in the early 2000s and Club Penguin was huge when I was a kid! Everyone my age knows about it.

      • Prison Mike
        link
        fedilink
        English
        5
        edit-2
        3 months ago

        I was born in the late 1980s, can I know what it is?

        Edit: Looks like a game. Are we assuming everyone in a technology community cares about video games? I’m a programmer but can’t get into video games at all.

        • Kokesh
          link
          English
          43 months ago

          I’m also a developer, online 24/7 since 1995 and have no idea.

        • @Crashumbc
          link
          English
          13 months ago

          Aren’t you assuming everyone else can’t care about video games because you don’t?

          Why does being a programmer matter? You’re not implying that technology groups should care about programming I hope.

          • Prison Mike
            link
            fedilink
            English
            2
            edit-2
            3 months ago

            I’m explaining why I’m a programmer for some context why I’m interested in technology, not to argue that all programmers hate gaming.

            I was replying against the smug “you must’ve been born in the 2000s” comment. I’m arguing that not everyone is into gaming just because this is a technology community, and to maybe drop the attitude because someone isn’t cOoL like them because they were born earlier. 🙄

          • @[email protected]
            link
            fedilink
            English
            -13 months ago

            They asked what’s club penguin, the person made a joke about their age. Be reasonable.

      • @Godric
        link
        English
        13 months ago

        I guess you were born in the 1950s, kids these days just don’t know…

  • umami_wasabi
    link
    fedilink
    English
    2
    edit-2
    3 months ago

    So what password hashing mechanism upgrades they implemented?