(no title)
adameasterling | 2 years ago
The Open Web Application Security Project's Application Security Verification Standard recommends that you do a hashed password check [2].
For bigger companies, sure, go talk to legal, but for young startups, my feeling is it's not worth the $200 or whatever your counsel will charge to say it's ok. I personally did not ask anyone (am cto), I just added the check.
1. https://twitter.com/troyhunt/status/1674132801837477888
2. See OWASP ASVS 4.0 2.1.7 https://github.com/OWASP/ASVS/blob/master/4.0/en/0x11-V2-Aut...
rockskon|2 years ago
That said I struggle to believe the sys admin had competent representation.
CoffeeOnWrite|2 years ago
no_wizard|2 years ago
Xorakios|2 years ago
Probably closer to $2000 than $200, but paying for an opinion is truthful, helpful and useful.
Kinda sucks that it's necessary