Reply to post: Re: @AC

Brit school software biz unchains lawyers after crappy security exposed

Anonymous Coward
Childcatcher

Re: @AC

"no, everyone's password was their student id used for tests!"

You'll be glad to know that the initial migration password I am setting on destination user accounts are md5sums calculated on a few bytes from (effectively) /dev/urandom, for each one. If the real source password doesn't sync and overwrite the random one then at least the account has a pretty decent password!

The default was to use the surname field!

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon