Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The Cigital-recommended way to hash your passwords is to use an HMAC/scrypt combo, with the HMAC key stored on the app server (not the database).

What Linode did may, or may not, be dumb. They are being tight-lipped so we can only guess.



Why would you use an HMAC for password storage? It's not like length extension attacks are relevant in that application.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: