GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    alcinnz (alcinnz@floss.social)'s status on Thursday, 28-Nov-2024 00:43:44 JST alcinnz alcinnz

    Beyond Bcrypt - Soatok:
    https://soatok.blog/2024/11/27/beyond-bcrypt/

    In conversation about 7 months ago from floss.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: i0.wp.com
      Beyond Bcrypt
      from Soatok
      In 2010, Coda Hale wrote How To Safely Store A Password which began with the repeated phrase, “Use bcrypt”, where the word bcrypt was linked to a different implementation for various pr…
    • Embed this notice
      alcinnz (alcinnz@floss.social)'s status on Thursday, 28-Nov-2024 04:01:12 JST alcinnz alcinnz
      • EVERYTHING'S COMPUTER

      @be I like studying the code anyways, & I'm pleased to find most opensource software handling authentication properly!

      Apparently WordPress aside...

      In conversation about 7 months ago permalink
    • Embed this notice
      alcinnz (alcinnz@floss.social)'s status on Thursday, 28-Nov-2024 04:34:52 JST alcinnz alcinnz
      • EVERYTHING'S COMPUTER

      @be We evidently have different standards.

      But by my standards of "do they hash passwords properly", uptake is good!

      In conversation about 7 months ago permalink
    • Embed this notice
      EVERYTHING'S COMPUTER (be@floss.social)'s status on Thursday, 28-Nov-2024 04:38:52 JST EVERYTHING'S COMPUTER EVERYTHING'S COMPUTER

      @alcinnz The best way to handle authentication I've found is using the Kanidm identity provider (https://kanidm.com), which encourages passwordless authentication and has no requirement for passwords, TOTP, nor email. It supports passwords and TOTP as fallback authentication methods, but those can be disabled per user group by the system administrator. By default, it requires either Webauthn or a combination of password + TOTP.

      In conversation about 7 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Kanidm
    • Embed this notice
      alcinnz (alcinnz@floss.social)'s status on Thursday, 28-Nov-2024 04:38:57 JST alcinnz alcinnz
      • EVERYTHING'S COMPUTER

      @be Sigh, debates over how to do things better leaves us stuck in the tedious old way!

      At least we've largely minimized the security disaster incurred...

      In conversation about 7 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.