Skip to content

[S5 Slides] Security in Web Applications

6.470.scripts.mit.edu
16 pointscostan3 comments
On HN

Comments

1) Don't use anything fast (like md5) to hash your passwords. Use many-rounds of md5 or sha-1, or use something specifically designed for password hashing like eksblowfish

2) Don't escape your SQL, use parameterized queries

How good is md5 plus a 4-character (digits, actually, in the slides) salt?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.