Rich Felker@RichFelker·Oct 16, 2021TIL busybox generates password salts from current time in usec. Does this matter? Probably not, but seems mildly sus.1211123
Rich Felker@RichFelker·Oct 16, 2021Replying to @IanColdwaterThe busybox cryptpw/mkpasswd utility, or passwd command.26
Daniel Micay@DanielMicayReplying to @RichFelker and @IanColdwaterI was curious so I checked to see if toybox was doing it wrong and that's sane: https://github.com/landley/toybox/blob/aa16e0e2ccb366835c2aec0cb2f6e0e52497ede5/lib/password.c#L26-L27…. I didn't know the BusyBox code was such an awful mess full of commented out code and hacks. Also, what the hell is up with that TLS support? https://github.com/mirror/busybox/blob/836b79211df3aeaba1b8b65c6db5ee6193172cc0/networking/tls_aes.c…github.comtoybox/password.c at aa16e0e2ccb366835c2aec0cb2f6e0e52497ede5 · landley/toyboxtoybox. Contribute to landley/toybox development by creating an account on GitHub.10:33 PM · Oct 16, 2021·Twitter Web App4 Likes