2 ms·
Good god, no. Here is much better advice, in much shorter form: If you're storing a password, use bcrypt or I'll bite your thumbs off. If you're making sure s
by codahale 17y ago
Good god, no. Here is much better advice, in much shorter form:
If you're storing a password, use bcrypt or I'll bite your thumbs off.
If you're making sure something hasn't been modified by someone and you absolutely can't use a signed GPG message, use HMAC-SHA256 and a constant-time comparison algorithm or I'll bite your thumbs off.
All the business about hash functions is like advice on how to build your own car brakes using a backyard smelter and a sand cast. You might get something of roughly the right shape and weight but someone's going to get hurt down the road.