Post
Topic
Board Bitcoin Discussion
Re: Hacked BitcoinTalk Data Finally Surfaces On Dark Net
by
mjsbuddha
on 06/09/2016, 07:46:09 UTC
I think that one extra step of security would be to have implemented a custom salt for every users password

Each hash has a unique 12-byte salt.

Quote
Also, from StackOverflow:

That's the same nonsense I was responding to.

Quote
Not all of the passwords in the database leak had that encryption :p

It's impossible to upgrade a user's hash until they log in, since their password isn't known. Those users never logged in since the hash algorithm was upgraded several years ago.

What year did you change the hashing algorithm? From what I saw in the database some users who didn't logon after 2012 were not in it.