Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Honestly, I would feel much more comfortable if sites publicly disclosed their password encryption strategy.

Funny you should mention that.

I thought at one point that I could set up a http://tosdr.org/ like database, showcasing the best password securities in use. You could have lists of the people using MD5, scrypt, bcrypt, and so forth. Think of it as a trophy case of password storage algorithms. My sticking point was finding the information, aside from looking at already leaked databases, you just have to go and ask the developers.

I emailed about 35 companies with a standard block of text asking if they were willing to disclose their scheme, the responses were mostly in the following:

• "our passwords are encrypted, you don't need to worry"

• "we can't disclose this for security reasons"

• "you're trying to hack us!"

I don't know what I expected really. We will have to stick to laughing at the atrocities listed on on http://plaintextoffenders.com/ .



> "you're trying to hack us!"

This sounds like the beginning of a pretty good blog.


Yeah, the lack of transparency is what made me explicitly mention it when creating Persowna (https://www.persowna.net/).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: