in reply to Ideas for "fixing" PerlMonks 1.0
Are passwords still stored as plaintext?
It is — unfortunately — no secret that pm stores its passwords in plaintext. There has been plenty of discussion about this. We won't rehash it here.
Is security by obscurity really considered a valuable defence against ze baddies
I'm not talking about security — as in, preventing accounts or the site as a whole from being hacked, or personal data getting exfiltrated — so much as not revealing how the sausage gets made. The admins do quite a bit to detect scammers and stymie trolls. We don't, for example, want you to know whom we have blocked, or how.
If the system for this site requires changing to achieve that, then it should be done.
I don't disagree. But, as has been mentioned many times, this system is very hard to change. It would be not only easier, but more advantageous in the long run, to build a new system from scratch, where everything is done The Right Way.
I am willing to put effort into that myself.
I appreciate that, and am grateful indeed.
|
---|
Replies are listed 'Best First'. | |
---|---|
Re^2: Ideas for "fixing" PerlMonks 1.0
by etj (Priest) on Dec 17, 2024 at 10:14 UTC | |
by Arunbear (Prior) on Dec 17, 2024 at 11:32 UTC | |
by etj (Priest) on Dec 18, 2024 at 08:59 UTC | |
by jdporter (Paladin) on Dec 18, 2024 at 14:21 UTC | |
by LanX (Saint) on Dec 18, 2024 at 14:35 UTC | |
| |
by LanX (Saint) on Dec 18, 2024 at 09:52 UTC | |
by erzuuli (Cannon) on Dec 18, 2024 at 14:18 UTC | |
| |
Re^2: Ideas for "fixing" PerlMonks 1.0
by etj (Priest) on Dec 17, 2024 at 10:01 UTC | |
Re^2: Ideas for "fixing" PerlMonks 1.0
by NERDVANA (Priest) on Dec 19, 2024 at 02:52 UTC |