Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Given the prevalence of password reuse, exposing user passwords is never a good idea.


Just to drive this home a little more: a lot of your users will use the exact same e-mail address and password on your site that they use for their bank. And while they shouldn't do that, they will, and that's why you should use best practices to protect your users' credentials even if their account on your site is completely unimportant.


Ah, yes, I missed the "I would bet the majority of those registered reuse the passwords." from parent.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: