Better crypto for storing passwords
authorRogdham <contact@rogdham.net>
Thu, 30 Aug 2012 14:40:02 +0000 (16:40 +0200)
committerRogdham <contact@rogdham.net>
Thu, 30 Aug 2012 14:53:33 +0000 (16:53 +0200)
commita88b78af17c080b81fecce19f17611ca921632d3
tree1ab2da527e7d4225f5175d277a52407d00686740
parentea22ed15253ede8591a26e4c7b91a8bf2abcadbc
Better crypto for storing passwords

Instead of hash(passwd), store hash(SALT, key, passwd) where:
 - SALT is application-specific
 - key is random and changed each time passwd changes

To login as admin the first time, go and see /login/1/victory
main.py
schema.sql