makinj / MeNext

Media request service with a hint of democracy!
MIT License
9 stars 3 forks source link

Salts should be unique to each user #60

Open wylermr opened 7 years ago

wylermr commented 7 years ago

Currently the password hash salt used is unique per-instance rather than per-user. This ignores half of the usefulness of salting. Each user should have their own unique salt.

(Not even sure if this project is still alive, just something I noticed flipping through)