Details
-
Sub-task
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
Description
Current password hashing implementation is pretty much useless against brute force/dictionary attacks.
see:
https://jira.springsource.org/browse/SEC-1472
http://www.win.tue.nl/cccc/sha-1-challenge.html