Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've heard 2 ways to do it:

1. Add a flag column to your password database; whenever anyone signs in without the flag set, encrypt their password the old way (for checking against their old entry in the database) and the new way (for storage in the database) and set their flag. The only trouble is, users who never log in don't get migrated.

2. It's possible to treat the old encrypted form of the password as if it's plaintext, salt that, encrypt with bcrypt, and store the result in the database. Then password checking becomes: encrypt password with old algorithm, salt, encrypt with bcrypt, and check against the database. It lets you convert everyone at once, but makes the login code a little more complicated, forever. If you can't convert everyone's database entry at once, you might still want a flag column, so you can migrate more gradually.

There are still all the usual headaches of QA, release management, etc., but presumably you already know how to handle them. What else am I missing?



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: