Menu

#94 Replace SHA1 hashing with something more secure

2.1.2
closed
nobody
security (1)
core
defect
trivial
core
2.1.0
2011-07-04
2011-04-25
No

By default, TG 2.1 uses SHA1 to encrypt passwords, which has been broken already 6 years ago (http://www.schneier.com/blog/archives/2005/02/sha1_broken.html), and using a general purpose hash function for storing passwords is not a good idea anyway (http://codahale.com/how-to-safely-store-a-password/). We should replace it with something better in 2.2.

Discussion