<em>not</em> be within the Web server's URI space -- that is, they should
not be fetchable with a browser.</p>
+ <p>This program is not safe as a setuid executable. Do <em>not</em> make it
+ setuid.</p>
+
<p>The use of the <code>-b</code> option is discouraged, since when it is
used the unencrypted password appears on the command line.</p>
+
+ <p>When using the <code>crypt()</code> algorithm, note that only the first
+ 8 characters of the password are used to form the password. If the supplied
+ password is longer, the extra characters will be silently discarded.</p>
+
+ <p>The SHA encryption format does not use salting: for a given password,
+ there is only one encrypted representation. The <code>crypt()</code> and
+ MD5 formats permute the representation by prepending a random salt string,
+ to make dictionary attacks against the passwords more difficult.</p>
</section>
<section id="restrictions"><title>Restrictions</title>