Skip to content

Next

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
    • Switch to GitLab Next
  • Sign in / Register
Minds Backend - Engine
Minds Backend - Engine
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Dependency List
    • Cycle Analytics
    • Insights
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
    • Locked Files
  • Issues 178
    • Issues 178
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Merge Requests 30
    • Merge Requests 30
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Packages
    • Packages
    • List
    • Container Registry
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • Minds
  • Minds Backend - EngineMinds Backend - Engine
  • Merge Requests
  • !18

Closed
Opened 1 year ago by Vinnie Marone@vmarone1
  • Report abuse
Report abuse

Use SHA256 for __elgg_session

Changed md5 hash to sha256.

Request to merge Porthorian:patch-1 into master
  • Email patches
  • Plain diff
Requires 2 more approvals from Devs and Deployers.
Mark Harding
Mark Harding
Brian Hatchet
Brian Hatchet
Rami Albatal
Rami Albatal
Ben Hayward
Ben Hayward
Marcelo Rivera
Marcelo Rivera

Closed by Mark Harding 38 minutes ago

The changes were not merged into master

  • Discussion 4
  • Commits 1
  • Changes 1
  • Loading...
  • Serkan-devel
    Serkan-devel @Serkan-devel · 1 year ago

    Who came to the idea to explicitly use md5 for hashing? It's even referenced in the whitpaper. I don't think I need to tell why md5 is insecure

  • Vinnie Marone
    Vinnie Marone @vmarone · 1 year ago

    I was a little surprised when, I saw that tbh. After all it is a deacentralized social network.

  • Mark Harding
    Mark Harding @markharding · 1 year ago

    md5 is used here as it is just very lightweight unique id for the server side session. There's not really any security issue with using md5 here as there aren't really any attack vectors such as brute force attacks that would really do anything.

    Passwords are hashed with bcrypt.

  • Serkan-devel
    Serkan-devel @Serkan-devel · 1 year ago

    Fair enough

  • Mark Harding @markeharding closed 38 minutes ago

    closed

  • You're only seeing other activity in the feed. To add a comment, switch to one of the following options.
Please register or sign in to reply
0 Assignees
None
Assign to
None
Milestone
None
Assign milestone
None
Time tracking
No estimate or time spent
0
Labels
None
Assign labels
  • View project labels
Lock merge request
Unlocked
10
10 participants
user avatar
Mark Harding
user avatar
Brian Hatchet
user avatar
Rami Albatal
user avatar
Ben Hayward
user avatar
Marcelo Rivera
user avatar
Martin Santangelo
user avatar
Emiliano Balbuena
Reference: minds/engine!18