Hacker Newsnew | past | comments | ask | show | jobs | submitlogin



While Coda's 2010 blog post is clearly the most commonly linked-to bcrypt reference – the post itself includes a many links including one to an article by Derek Slager (quoting tptacek) from 2007, links t both Java and Perl implementations from 2006, and a link to a Usenix paper from 1999.

If Adobe didn't switch to intentionally-slow hashes with proper salting until "last year", that puts them over 20 years behind "best practice" (as well as 2 or 3 years behind fully deserving of online mockery, laughable uninformed-newbie levels of security engineering).


The article also states they switched to sha-256. Best I'm aware, that algorithm isn't adaptive, so they may have just as well used md5.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: