Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Quite surprised at the number of people who are worried about this, it's hardly complicated..


It's almost like I acknowledged that there were ways of doing it but expressed concerns for/of doubt that it was being done in the proper fashion due to the misguidedness of it.

I'll say for a third time, as you're not the first person to reply in kind, I'm more than well aware of ways this could be done, but none of them meet the typical expectation of how passwords are hashed and I would guess/assume that someone is far more likely to be insecurely storing passwords than going out of their way to store a... reduced entropy version of users' passwords in their database.


They're using SRP, which dictates that they're storing passwords (relatively) securely on their side. You don't have to guess; this stuff has been reversed.


Storing un-hashed passwords (encrypted or otherwise)?

I'm largely unaware of crypto outside of the general "use bcrypt" webapp cases. SRP is a fairly unknown field to me.

Edit: nevermind, you more or less confirmed this question further down this thread[1], and [2]

[1] http://news.ycombinator.com/item?id=4022996

[2] http://news.ycombinator.com/item?id=4023034




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: