<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to: Ensure your Linux account passwords are strongly hashed</title>
	<atom:link href="http://r3dux.org/2011/07/how-to-ensure-your-linux-account-passwords-are-strongly-hashed/feed/" rel="self" type="application/rss+xml" />
	<link>http://r3dux.org/2011/07/how-to-ensure-your-linux-account-passwords-are-strongly-hashed/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-to-ensure-your-linux-account-passwords-are-strongly-hashed</link>
	<description>A number-pimping side project from the valleys in *NEW* upside-down flavour.</description>
	<lastBuildDate>Tue, 15 May 2012 23:01:55 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: r3dux</title>
		<link>http://r3dux.org/2011/07/how-to-ensure-your-linux-account-passwords-are-strongly-hashed/#comment-6885</link>
		<dc:creator>r3dux</dc:creator>
		<pubDate>Mon, 01 Aug 2011 10:07:54 +0000</pubDate>
		<guid isPermaLink="false">http://r3dux.org/?p=4873#comment-6885</guid>
		<description>True - the VPS distro this is hosted on definitely isn&#039;t the latest and greatest (and I&#039;m fine with that), so I guess that means I&#039;d have to find out at which version of Ubuntu they switched from MD5 to SHA hashes.

Saying this, because it&#039;s my VPS, I&#039;ve updated the software on it as I&#039;ve gone along, so maybe that&#039;s something to do with it as well. You definitely can&#039;t do a kernel upgrade (as part of a dist-upgrade) because how would that interact with the Xen stuff? [like an axe to the head, I&#039;d imagine!]

Knackered my site the other day trying to twiddle with options and it just lost all the css config... Still chasing issues in css land, but at least I get to go through and give it a much needed cleanup... It&#039;s been non-validating since day 1, so it&#039;s well time I did something about it. (i.e. Do you like the .commentlist unordered list thingies to the left of embedded comments? Me neither! Haw haw... =P )</description>
		<content:encoded><![CDATA[<p>True &#8211; the VPS distro this is hosted on definitely isn&#8217;t the latest and greatest (and I&#8217;m fine with that), so I guess that means I&#8217;d have to find out at which version of Ubuntu they switched from MD5 to SHA hashes.</p>
<p>Saying this, because it&#8217;s my VPS, I&#8217;ve updated the software on it as I&#8217;ve gone along, so maybe that&#8217;s something to do with it as well. You definitely can&#8217;t do a kernel upgrade (as part of a dist-upgrade) because how would that interact with the Xen stuff? [like an axe to the head, I'd imagine!]</p>
<p>Knackered my site the other day trying to twiddle with options and it just lost all the css config&#8230; Still chasing issues in css land, but at least I get to go through and give it a much needed cleanup&#8230; It&#8217;s been non-validating since day 1, so it&#8217;s well time I did something about it. (i.e. Do you like the .commentlist unordered list thingies to the left of embedded comments? Me neither! Haw haw&#8230; =P )</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shetboy</title>
		<link>http://r3dux.org/2011/07/how-to-ensure-your-linux-account-passwords-are-strongly-hashed/#comment-6884</link>
		<dc:creator>shetboy</dc:creator>
		<pubDate>Mon, 01 Aug 2011 09:47:17 +0000</pubDate>
		<guid isPermaLink="false">http://r3dux.org/?p=4873#comment-6884</guid>
		<description>That depends on what distro THEY are using, and how old it is.

I would imagine that they wouldn&#039;t upgrade TOO often, businesses tend to lie far behind the curve in these things.  Just think of all the hassles they get whenever they change the OS of their servers?  Something that I wouldn&#039;t do without being forced to, something like the security updates being at EndOfLife.

It&#039;s simple business logic, if the system works then don&#039;t mess around with it.  Nothing worse than riling up your customer base every six months for an upgrade, which most of the time would yield very little benefit to the business.

Even when support is at EOL they would likely add it to their TODO task list and fit it in whenever it&#039;s best for them.</description>
		<content:encoded><![CDATA[<p>That depends on what distro THEY are using, and how old it is.</p>
<p>I would imagine that they wouldn&#8217;t upgrade TOO often, businesses tend to lie far behind the curve in these things.  Just think of all the hassles they get whenever they change the OS of their servers?  Something that I wouldn&#8217;t do without being forced to, something like the security updates being at EndOfLife.</p>
<p>It&#8217;s simple business logic, if the system works then don&#8217;t mess around with it.  Nothing worse than riling up your customer base every six months for an upgrade, which most of the time would yield very little benefit to the business.</p>
<p>Even when support is at EOL they would likely add it to their TODO task list and fit it in whenever it&#8217;s best for them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: r3dux</title>
		<link>http://r3dux.org/2011/07/how-to-ensure-your-linux-account-passwords-are-strongly-hashed/#comment-6883</link>
		<dc:creator>r3dux</dc:creator>
		<pubDate>Mon, 01 Aug 2011 08:04:04 +0000</pubDate>
		<guid isPermaLink="false">http://r3dux.org/?p=4873#comment-6883</guid>
		<description>Good to know, cheers!

It&#039;s definitely $6$ on my copy of 11.04, too - but for some reason some of my VPS accounts were $1$, so MD5! Curiouser &amp; curiouser =D</description>
		<content:encoded><![CDATA[<p>Good to know, cheers!</p>
<p>It&#8217;s definitely $6$ on my copy of 11.04, too &#8211; but for some reason some of my VPS accounts were $1$, so MD5! Curiouser &amp; curiouser =D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shetboy</title>
		<link>http://r3dux.org/2011/07/how-to-ensure-your-linux-account-passwords-are-strongly-hashed/#comment-6882</link>
		<dc:creator>shetboy</dc:creator>
		<pubDate>Mon, 01 Aug 2011 06:52:11 +0000</pubDate>
		<guid isPermaLink="false">http://r3dux.org/?p=4873#comment-6882</guid>
		<description>Interesting... after doing a new install of Ubuntu 11.04 this weekend I thought I&#039;d check the default setup.  I can confirm that the distro does a $6$ encryption straight away.</description>
		<content:encoded><![CDATA[<p>Interesting&#8230; after doing a new install of Ubuntu 11.04 this weekend I thought I&#8217;d check the default setup.  I can confirm that the distro does a $6$ encryption straight away.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

