3 ms·
There are things to be learned from the article at more levels than just the design of new protocols. For example, I would say this good advice that applies to
by by 17y ago
There are things to be learned from the article at more levels than just the design of new protocols. For example, I would say this good advice that applies to ordinary smart people:
"Do NOT store users' passwords. Do NOT hash them with MD5. Use a real key derivation algorithm. PBKDF2 is the most official standard; but scrypt is stronger.
Please keep in mind that even if YOUR application isn't particularly sensitive, your users are probably re-using passwords which they have used on other, more sensitive, websites -- so if you screw up how you store your users' passwords, you might end up doing them a lot of harm."