Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

By salted hashes, I'm pretty sure OP meant using something like bcrypt or PBKDF2


Thanks, yes, using bcrypt. Usually just with something like PHP's password_hash() and the default algorithm. I sort of expected to trigger people with my post, and it's enlightening, but I feel pretty safe with what I'm doing. I mean, I like to know exactly how everything in my engine works. But there's a point at which I can't get paid to reinvent the wheel anymore, nor do I want to try.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: