dropbox / dropbox/zxcvbn

Enhance documentation with a security advice

Open
#147 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
CoffeeScript
Stars
16.1k
Forks
1k
PR merge metrics
No merged PRs in 30d

Description

Hi,

I did read [this](http://gavinmiller.io/2016/a-tale-of-security-gone-wrong/) blog post. I think this blog post explains very well why it is a bad idea to store information gathered by zxcvbn together with
the password. In my point of view even within log-files you should handle these values like passwords themselfes.

Maybe this way somebody else will not make the same mistake.

regards
dieter

Contributor guide

No contributing guide indexed for this repository

Research direction

No target documentation file, test, or entry point is named. Read the repository documentation to find the appropriate place for a security warning based on the linked blog post, and define completion as clearly advising users not to store zxcvbn-derived values with passwords or in log files.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.