Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Passwords shouldn't be encrypted anyway. Chances are hackers will be able to obtain the key too, and then passwords are really easy to fetch.

Passwords should be hashed non-reversible (ideally using a slow hash). The original password is to no use of the application.

And sending plain-text passwords to users is even more bad[1].

[1]: http://plaintextoffenders.com/



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: