09-23-2017, 09:38 PM
Can you add those to the doc?
It pretty much breaks all security if we ever know the password.
Even if we only store the password when they change it (ie, they enter their old password, it confirms it, then we store it), that's pretty dangerous because of the way people reuse passwords. I guess technically we could store the bcrypted old one too, but I still think it's an issue.
Awesome. We'll get your stuff out. 4 alphas in 1 day. That's progress.
It pretty much breaks all security if we ever know the password.
Even if we only store the password when they change it (ie, they enter their old password, it confirms it, then we store it), that's pretty dangerous because of the way people reuse passwords. I guess technically we could store the bcrypted old one too, but I still think it's an issue.
Awesome. We'll get your stuff out. 4 alphas in 1 day. That's progress.