[wp-hackers] New password hashing algo in trunk

Jared Bangs jared at pacific22.com
Mon Dec 24 01:08:50 GMT 2007


On Dec 23, 2007 4:36 PM, Jeremy Visser <jeremy.visser at gmail.com> wrote:
> I don't quite get it. WPMU stays in sync with WP anyway, so the WPMU
> version released after WP 2.4 is released will have the new hashing
> functionality anyway.

That may be, but I'd like to have those security issues plugged
sooner. I was just throwing this out there for anyone who may want the
same, while they wait for the next version. If anyone would rather
wait for the version release, they're welcome to.

On a related note, since the admin reworking is being checked into the
WP trunk now, I'd guess that will probably have an impact on the next
WPMU release date, if the plan is still to keep them in sync
feature-wise.

Someone may have already mentioned this on here (since I haven't read
every thread recently), but it seems to be pretty close to the release
date for those kind of changes to be going in, but I admittedly am not
familiar with the nature of the admin changes, so maybe it's not as
big a deal as I'm thinking.

Either way, all this patch was is an early sync (from WP to WPMU) of
just these two specific security patches (using Ryan's code line for
line), and I'd just rather use those while I wait for the next
release.

I know that there are a lot of people with MU installations (with lots
of users) who are feeling vulnerable, so I just wanted to get that out
there early. Didn't mean to step on anyone's toes there; sorry if
that's how it came across.

- Jared


More information about the wp-hackers mailing list