Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The same way you're able to login to News.YC without sending your actual password via the intertubes.


I'm not sure I understand you; CC numbers are not passwords. You can't salt and hash them on one end and then confirm on the other end; you need to send the whole number if you expect to process a charge against it.


The HN login sends your password over the internet. It doesn't even use SSL. It is in the clear, readily visible to anyone able to run a packet sniffer on your traffic.


But you do send your actual password... The hashing occurs on the server. Also, this has nothing to do with credit cards. They are not passwords.


You mean "not at all"? Just fire up a packet sniffer...


So some sort of public-key cryptography?

I didn't realize that the HN login page didn't send a password on a login.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: