We know that MD5 is bad, and we definitely want to stop using it. Unfortunately, the MyBB 1.8 series has a commitment to supporting PHP 5.2, which doesn't support any of the methods we'd be looking to move to (eg: BCrypt, or Argon). A future feature release will definitely update the algorithm, as well as improving the way that sessions work and we should see 2FA support for users as well as administrators.

