Given the frequent break-ins and some of the messages stating how md5 has been hacked, what is the recommended way for configuring password-encoding in Spring Security?
Also, if you already have password-encoding set up with spring security, how would you migrate encoded password to a new strategy should you choose one?
Marc
