[Catalyst] Re: Outcome of the Security issue with hashed passwords in C:P:A:Password?

2010-04-10 Thread Aristotle Pagaltzis
* Andrew Rodland and...@cleverdomain.org [2010-04-10 09:00]: the complexity of storing them separately Does not compute. Regards, -- Aristotle Pagaltzis // http://plasmasturm.org/ ___ List: Catalyst@lists.scsys.co.uk Listinfo:

[Catalyst] Re: Outcome of the Security issue with hashed passwords in C:P:A:Password?

2010-04-09 Thread Daniel Pittman
Andrew Rodland and...@cleverdomain.org writes: On Thursday 08 April 2010 08:12:24 pm Toby Corkindale wrote: On 08/04/10 22:49, Daniel Pittman wrote: ...but your lost database *also* exposed user account/password pairs, which can now be tried against other services, since people usually use

[Catalyst] Re: Outcome of the Security issue with hashed passwords in C:P:A:Password?

2010-04-08 Thread Daniel Pittman
Toby Corkindale toby.corkind...@strategicdata.com.au writes: On 08/04/10 16:21, Andrew Rodland wrote: * In what circumstances was an attack possible? ie. What combination of modules, options, auth methods. * You use Catalyst::Authentication::Credential::Password. * With the hashed

Re: [Catalyst] Re: Outcome of the Security issue with hashed passwords in C:P:A:Password?

2010-04-08 Thread Toby Corkindale
On 08/04/10 22:49, Daniel Pittman wrote: Toby Corkindaletoby.corkind...@strategicdata.com.au writes: On 08/04/10 16:21, Andrew Rodland wrote: * In what circumstances was an attack possible? ie. What combination of modules, options, auth methods. * You use

Re: [Catalyst] Re: Outcome of the Security issue with hashed passwords in C:P:A:Password?

2010-04-08 Thread Andrew Rodland
On Thursday 08 April 2010 08:12:24 pm Toby Corkindale wrote: On 08/04/10 22:49, Daniel Pittman wrote: ...but your lost database *also* exposed user account/password pairs, which can now be tried against other services, since people usually use the same weak password and username all over