Vanilla 1 is no longer supported or maintained. If you need a copy, you can get it here.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.
Vanilla with a pinch of salt...
Just curious if there was a reason why I don't see any salting of the password hash in Vanilla. MD5 has been around long enough that if you know the MD5 value, you have a good chance of looking up what the password may be.
0
This discussion has been closed.
Comments
Plus, to change the way passwords are handled would be a huge pain in the ass for people upgrading to the new version with existing forums.
Regardless, what Vanilla has is industry standard and completely acceptable.
This thread was at the top but the post before this one says 1 day ago. I should've screenshotted. Sorry.