Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wow, you jumped right on that :) I deleted the comment immediately after posting it because I wasn't really sure I could support that statement. As someone who doesn't know a lot about security algorims, I'm susceptible to the idea posed in the article that the better-proven algorithm is a safer bet; but on second thought, it seemed a little paranoid, since I haven't seen any positive reason to doubt bcrypt's security. And given that PBKDF2 is an uglier thing to try to recommend, and "just use something" is the most important message, I think the current atmosphere around bcrypt is probably fine.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: