Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is why you shouldn't "innovate" with encryption unless you are a trained cryptographer (or equivalent). Cryptographers may be programmers, but programmers are not cryptographers.


You don't need to be a cryptographer to know that you don't do plaintext passwords.


But it seems it wasn't obvious to bullen that this way the password is essentially sent in plain text. So yes, let your authentication be analyzed by an expert or use standard software.


to state the obvious: there are other things you don't do




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: