2016-05-31 22:00:59 +00:00
|
|
|
|
|
|
|
=== Password database compromised
|
|
|
|
|
2017-08-28 12:50:14 +00:00
|
|
|
{project_name} does not store passwords in raw text.
|
2016-05-31 22:00:59 +00:00
|
|
|
It stores a hash of them using the PBKDF2 algorithm. It actually uses
|
2016-09-02 18:49:29 +00:00
|
|
|
a default of 20,000 hashing iterations! This is the security community's recommended number of iterations.
|
2016-05-31 22:00:59 +00:00
|
|
|
This can be a rather large performance hit on your system as PBKDF2, by design, gobbles up a significant amount of CPU.
|
|
|
|
It is up to you to decide how serious you want to be to protect your password database.
|
|
|
|
|