Quote:
Originally Posted by BlueMelon
Even if it was with md5 it would be fine considering we use generated passwords...
|
Not everyone uses a generated password, and that's still no excuse. Ideally Graal would start using session tokens that are unique to each installation like most other services with a "remember me" feature. Then you could easily void saved sessions if you accidentally checked "remember me" on a friend's computer or something.