[wp-trac] [WordPress Trac] #11813: Post password stored as plaintext

WordPress Trac wp-trac at lists.automattic.com
Mon Sep 17 15:21:05 UTC 2012


#11813: Post password stored as plaintext
---------------------------+-----------------------------
 Reporter:  ericmann       |       Owner:  ryan
     Type:  defect (bug)   |      Status:  new
 Priority:  normal         |   Milestone:  Future Release
Component:  Security       |     Version:  2.9.1
 Severity:  normal         |  Resolution:
 Keywords:  post-password  |
---------------------------+-----------------------------

Comment (by ericmann):

 Replying to [comment:6 nacin]:
 > It's something that is designed to be shared, so storing it hashed is
 pretty much a no-go.

 Good point.

 > Perhaps calling it something other than a "password" would also help,
 but that ship has sailed.

 Perhaps we could rename it in a future release? It won't be the first time
 we've renamed a feature. (Admin bar => toolbar)

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/11813#comment:7>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list