On Fri, 2006-12-29 at 14:47 -0800, Ryan Roth wrote:
> idea of plain text passwords.  If you really want I can change it to 
> md5, but since the username and password are salted with each other it 
> should be pretty safe, since you would need both to crack one.

Hashing the username seems like needless obfuscation.  What you're
essentially doing is concatenating the username and password to make a
bigger password, both of which now are considered key material.  But the
username shouldn't be used as key material, because it's always visible
in logs, echoed back when the user types it, etc.  So you're not really
improving security by doing this.

I'd just follow the traditional model and store the username and the
crypted password.  You can use python's crypt module to hash the
password with a random salt.  (Specify "$1$<salt>$" as the salt
parameter and it will use MD5 to hash the password.)

Cheers,
Jason.


-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Freevo-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/freevo-users

Reply via email to