But then how would they ever migrate beyond sha1? Would the hundred-year language save passwords in a way that gets more insecure every year?
I think arc's default assumption is that there's no difference between 'inside' and 'outside'. And this is how lisp used to be.
(sha512 (+ (sha1 pw) user-salt site-salt))
BTW, for security, it is also unsecure to pass unhashed passwords around network, unless use https.
-----
Yes. Though you can get that with apache or nginx.