Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Hash it on the client? So are you not using salted hashes for your password store?

There is no reason you can't also salt on the client. Salts do not need to be secret. The substantial constraint you outlined in your comment isn't a problem.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: