Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If they are worried about user experience and that is the main reason they do not encrypt - then why not at the very least use a version of encryption that the site can decrypt? Sure, the people who grab the data can run some cryptography programs on it and eventually come up with the algorithm, but it is a hell of a lot safer than plain text.


We don't really know if they are encrypting the password while storing in the db.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: