Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sorry, reading that again I sound like a dick. I know it's a common error and I didn't mean to nitpick.

I only mention it because there's an important difference in that with hashing, it doesn't really matter as much what the strategy is, since a bad password is a bad password. Better hashing only means a lower percentage of your intermediately-secure passwords are compromised right away. Since they (should) have no way of knowing which passwords are secure, they have to treat them all as compromised even if they were storing them "right".



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: