Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you're worried about the NSA or other nation-states then I wouldn't stop with hashing+salting. You need to be using something like scrypt/bcrypt/PBKDF2. cperciva has a paper about scrypt, bcrypt is at least widely known for this use case, and PBKDF2 is even a "certified" way to do that.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: