Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If I understood you correctly - there doesn't need to be a tradeoff between wire and storage security.

You could use a oneway hash at the client side as well.

If you don't want to divulge what's the hash in your database, you can add another oneway hash for whatever reaches the server.

The challenge-response can also be based on hashes.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: