Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I used this strategy years ago (2002) to migrate plaintext passwords in a site with 50k+ users. In fact, I built this into the system so I could do arbitrary migrations between password encodings whenever I felt it was necessary.

It works well.



Ruby and Django could do well to have this type of strategy baked in. This way you update your configuration and the passwords are immediately upgraded.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: