HN2new | past | comments | ask | show | jobs | submitlogin

It is very dangerous to be ignorant about critical computer science fields like cryptography and just go with the cult.

I'm not saying you should build your own cryptography, but a good hacker (or a good engineer how we call them in early 90s) should understand difference between bcrypt, PBKDF2, and scrypt. At least to understand why bcrypt is better than salt+SHA-1. And some other aspects of security.

However, if somebody has no clue about cryptography and security then she/he should go with bcrypt - but I'm not sure if that person should be responsible or in business of storing somebody's critical data at all.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: