couchdb-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From KlausTrainer <...@git.apache.org>
Subject [GitHub] couchdb pull request: Upgrade password hashes on authentication
Date Wed, 19 Feb 2014 10:59:35 GMT
Github user KlausTrainer commented on the pull request:

    https://github.com/apache/couchdb/pull/152#discussion_r9861018
  
    Btw., I also realized that the way I did the password hash upgrade here would totally
introduce a security hole that would random people allow to choose an arbitrary new password
if the existing password would be hashed with the old password scheme.


---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. To do so, please top-post your response.
If your project does not have this feature enabled and wishes so, or if the
feature is enabled but not working, please contact infrastructure at
infrastructure@apache.org or file a JIRA ticket with INFRA.
---

Mime
View raw message