You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Tekki wrote: "By the way, the idea of using long passwords doesn't improve the security as long as we don't change the password encryption. The crypt function only considers the first 8 characters of the password and discards the rest. This means from character 9 onward you can type whatever you want. We should change this as soon as possible."
Thank you pointing at this issue. I think it is better to keep it as an open issue here. This is important especially for the SL instances open to the internet.
We would appreciate if you change password hashing to a stronger one whenever you have time.
The text was updated successfully, but these errors were encountered:
sse450
changed the title
Weak password because of poor crypt hashing
Weak password because of poor encryption of crypt function
May 6, 2024
Tekki wrote: "By the way, the idea of using long passwords doesn't improve the security as long as we don't change the password encryption. The
crypt
function only considers the first 8 characters of the password and discards the rest. This means from character 9 onward you can type whatever you want. We should change this as soon as possible."Thank you pointing at this issue. I think it is better to keep it as an open issue here. This is important especially for the SL instances open to the internet.
We would appreciate if you change password hashing to a stronger one whenever you have time.
The text was updated successfully, but these errors were encountered: