6 ms·
Compromising the integrity of the npm registry
- JoachimSchipper 15y agoQuote: "It took only 24 hours using an old spare machine to crack 25% of the passwords. Very little effort or CPU power." Time for another "use bcrypt", methinks.
- evilpacket 15y agoCouchdb has an open ticket on this very issue, which is part of the problem. The other part is the fact that they have really nonsensical configuration defaults. https://issues.apache.org/jira/browse/COUCHDB-1060 https://issues.apache.org/jira/browse/COUCHDB-1060
- SaltwaterC 15y agoIt looks like "security in deployment" (aka sane defaults) is a concept difficult to grasp for the CouchDB devs. I wouldn't expect this from a project that claims it is passed over version 0.x.