4 ms·
Obligatory http://codahale.com/how-to-safely-store-a-password/ http://codahale.com/how-to-safely-store-a-password/ link which taught me a ton.
by gaving 15y ago
Obligatory http://codahale.com/how-to-safely-store-a-password/ http://codahale.com/how-to-safely-store-a-password/ link which taught me a ton.
- misterbwong 15y agoThank you. This article is quick and easy to digest and understand. There's always a lot of whining and complaining about how {crappyhash} algorithm is bad and how salts don't matter but not a lot a of {dothisinstead}.
- sdkmvx 15y agoI see that link referenced a lot and don't think that's a good thing. He's right, but he doesn't explain why we should use bcrypt (or any other adaptive password hashing function). Picking bcrypt without knowing why is just as bad as picking MD5 without knowing why.
- mentat 15y agoNo, it's really not, as long as you follow current guidance on counts for iteration. There are people smarter than <x> random person and sometimes (often with crypto) it's better to follow their advice. Anyone can make a system that they themselves cannot break. Don't be that person.
- sdkmvx 15y agoI strongly disagree. If you are the person tasked with implementing password verification, then you really should learn enough about the field to give a rough explanation of why you've used bcrypt (or whatever you use). If you know what MD5 (and other simple hashes)'s deficiency is (and Hale explains it), then you should know how bcrypt, etc. solve that problem. One should follow expert advice but not blindly.
- rsiqueira 15y agoThis is the HN discussion and comments about this article (How To Safely Store A Password): http://news.ycombinator.com/item?id=2004833 http://news.ycombinator.com/item?id=2004833