Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Exactly right, and I'm trying to say that too!

My point is that although password hashing is a very wise practise, there are situations in which the plaintext is necessary, and with careful design a plaintext password store can be made no weaker in security than the rest of the system.

This seems to me to be common sense and I have no idea why it's so controversial.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: