Hacker News new | past | comments | ask | show | jobs | submit login

Because sha1 is still super fast on a GPU. Why aren't you using bcrypt?



I thought that hashing password with two types of salt (one of them is unique for every user) and two places to storage salts is secure enough.


You thought wrong.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: