Simple Machines Community Forum

SMF Support => SMF 2.0.x Support => Topic started by: rcane on September 24, 2024, 02:51:06 PM

Title: SHA-1 passwords and improving
Post by: rcane on September 24, 2024, 02:51:06 PM
How insecure is SHA-1 compared to other algorithms out there?

Is it a monumental task to swap it out on a 2.0 install for something more secure?

Title: Re: SHA-1 passwords and improving
Post by: vbgamer45 on September 24, 2024, 03:20:45 PM
Decently secure. Still requires a lot of work since there is a salt as well. It only matters if your database gets leaked, insecure software.
People could then discover a users password then try on other sites.

2.1.x uses bycrpt more secure
Title: Re: SHA-1 passwords and improving
Post by: Kindred on September 24, 2024, 04:39:35 PM
And yes, it's not minor to change it. That's why the change was fine in 2.1 and not as a patch to 2.0