Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One way requires the user to have a drastically stronger password to be safe, and the other significantly strengthens passwords, protecting a subclass of users that will always exist (those that are unable to remember strong passwords or don't know enough about the dangers of password cracking to know how to effectively choose passwords).

It is madness to defend the use of MD5 for password hashing these days. It is clearly not designed for that at all.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: