a thoughtful web.
Good ideas and conversation. No ads, no tracking.   Login or Take a Tour!
comment by dublinben
dublinben  ·  4323 days ago  ·  link  ·    ·  parent  ·  post: Hubski Update: Salt, save, akkartik

Are you using bcrypt for your password hashes? Using a computationally slow algorithm is just as important as salting your hashes for protecting the password database.





mk  ·  4322 days ago  ·  link  ·  

We aren't. It has been implemented in Arc for HN, however. We are either going to have to do it ourselves, or hope for an update from pg.

We'll keep moving in the right direction here.

dublinben  ·  4322 days ago  ·  link  ·  

Sounds like you know what you're doing. As a non-programmer, that's one of the few things I took away from the big password leaks of last year.