Improving Security of Stored Passwords in MyBB 1.8.x
#8
Quote:Encrypting the hashes is generally a better idea - the encryption key works as a pepper that can be changed/rotated (which cannot be done with salts).

I wasn't aware of the technical term "pepper" but it's exactly what I was suggesting.
Reply


Messages In This Thread
RE: Improving Security of Stored Passwords in MyBB 1.8.x - by User 2877 - 2020-01-20, 06:57 AM

Forum Jump:


Users browsing this thread: 1 Guest(s)