> Honestly, I would feel much more comfortable if sites publicly disclosed their password encryption strategy.
Funny you should mention that.
I thought at one point that I could set up a http://tosdr.org/ like database, showcasing the best password securities in use. You could have lists of the people using MD5, scrypt, bcrypt, and so forth. Think of it as a trophy case of password storage algorithms. My sticking point was finding the information, aside from looking at already leaked databases, you just have to go and ask the developers.
I emailed about 35 companies with a standard block of text asking if they were willing to disclose their scheme, the responses were mostly in the following:
• "our passwords are encrypted, you don't need to worry"
• "we can't disclose this for security reasons"
• "you're trying to hack us!"
I don't know what I expected really. We will have to stick to laughing at the atrocities listed on on http://plaintextoffenders.com/ .
Funny you should mention that.
I thought at one point that I could set up a http://tosdr.org/ like database, showcasing the best password securities in use. You could have lists of the people using MD5, scrypt, bcrypt, and so forth. Think of it as a trophy case of password storage algorithms. My sticking point was finding the information, aside from looking at already leaked databases, you just have to go and ask the developers.
I emailed about 35 companies with a standard block of text asking if they were willing to disclose their scheme, the responses were mostly in the following:
• "our passwords are encrypted, you don't need to worry"
• "we can't disclose this for security reasons"
• "you're trying to hack us!"
I don't know what I expected really. We will have to stick to laughing at the atrocities listed on on http://plaintextoffenders.com/ .