Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I thought salting+hashing was primarily to mitigate damage in an event of someone scooping the credentials data store. And/or bruteforcing.

If there were one login system/site in the whole world, you'd still want to hash/encrypt them.

I mean hashing is one of the easiest things to do to add a layer of security, so even if the db is encrypted, why not? Maybe I'm missing your point.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: