- 21comments
- 96comments
- 13comments
- 194comments
- 33comments
- 9comments
- 35comments
- 59comments
- 233comments
- 10comments
- 141comments
- 71comments
- 17comments
- 39comments
- 165comments
- 135comments
- 13comments
- 107comments
- 84comments
- 22comments
- 8comments
- 224comments
- 6comments
- —discuss
- 15comments
- 213comments
- 85comments
- —discuss
- 16comments
- 73comments
Good summary: https://twitter.com/PwdRsch/status/1103021803503607808
As an industry, we (developers) have a long way to go.
Maybe the segment of in the industry in which the cheapest outsourced devs work, anyway.
Their conclusion states as much (hiring more expensive devs on freelancer.com got them more secure solutions):
"In addition, we found a significant effect in the freelancers’ acceptance rate between the €100 and €200 conditions for the prompted task and examined the effect of different payment levels on secure coding behavior. We saw more secure solutions in the €200 conditions, although the difference was not statistically significant. However, this result might be due to the small sample size and we believe this is worth following up in future work."
They also state it's not statistically significant :P
(Although I agree that seems likely because of the sample size)
I am freelancing on my 10th year now (never set foot in an office to work), and let me tell you hiring people on freelancer.com, no matter how much the budget is, won't end up good.
Fiver and freelancer.com has the worst kind of freelancers in my experience.
It's insane to me that it's not "common knowledge" to AT LEAST hash the passwords.
It's also interesting because 6 used an encryption algorithm, 10 used MD5 which is as good as plaintext nowadays IMO, and 8 used Base64, so even though 24 people thought they "secured it" the passwords are trivial to recover.
MD5 is a little better than plaintext. Difficult passwords are still difficult when you know their MD5 hash.
Base64... is actually plaintext; that's much, much worse.
Yeah MD5 is better to a degree, although 5f4dcc3b5aa765d61d8327deb882cf99 is still the most common password (md5 hashed) hehe :P
To play devil’s advocate, to me plaintext means I want to finish quickly because you haven’t asked and are paying too little, while any solution other than bcrypt/pbkdf2 means I don’t know what I’m doing.
Having once run my own freelance web dev company, I feel very comfortable saying that I would not take a project where I wasn't getting paid enough to bother hashing passwords. That's beyond justification. Either reject the client or protect their users.
How much time does it take you to drop in bcrypt?
This should be part of the job, no matter how tight the budget is. Password hashing is quite accessible in almost every language and I can't think of any excuse not to hash passwords.
Some sources now recommend argon2 over those two, could that be another right answer?
Right? You literally have to go OUT OF YOUR WAY to not be exposed to hasing/salting - every framework does it, most tutorials include it, for most environments its a simple library import/api.
I have to wonder how they sourced their developers. I don't think researchers would be motivated to do much more then post a low bidding ad on craigslist, meaning the quality of the developers will be commiserate.
It's inside the paper. They used Freelancer.com and gave 100EUR/200EUR to 100 developers. They created a fake company website and asked the devs to completed the sign-up portion of their fake social network because of one of their fake developers resigned recently.
They used 2 tier of payment to see if the payment had an effect on the security of the code.
I'm curious as to why they only said 3 of 17 used salt -- most bcrypt implementations will automatically generate a random salt (since the salt is visible in the generated hash), and 7 people used bcrypt?
Literally bcrypt and you're done (for now).
Emphasis added.
ahhh thank you I did not read closely enough
What was the task they were asked to perform? For most work a contract under 1k isn't going to get you an extremely high quality developer. In finding, planing, negotiating, and implementing a project you accrue a lot of billable overhead time.
If you assume it takes....
Then at $200 you're making $66/hr. I'd classify myself as an average developer and most contract work people spam me me with on LinkedIn is in the $150/hr + benefits range.
I wonder what kind of quality they'd get with a larger project priced at that range. Something with 15hr of work @ $150 might bring in higher quality freelancers that are closer to the industry average.
Sounds like an expensive study
I understand your point but that also depends on the geographic location of the developer. 66 US Dollars here in Brazil – as well in many other countries – is an excellent rate and you find top notch developers. Even with half of that you would find excellent and experienced developers around here.