Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
theg
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
theg
18y ago
Your method for storing the passwords server-side is actually not very secure. Hashing the passwords without a unique salt is not a secure way to store them. For one thing, every user with the password of 'secret' will have the same hash
2.
▲
by
theg
18y ago
You can't have it both ways. If you are hashing the password before it is sent from the client to the server, you need the raw password on the server side. (Assuming you are concatenating it with a server-provided random value before the h