Skip to content

Comment on A New, Simple Way to Salt your Hashesparent

Comments

OK, you agree SSL does protect savvy users from MITM attacks.

You're talking about users who can be tricked into what are essentially non-SSL or degraded SSL (certificates from untrustworthy authorities) sessions, because they misread the URL bar or ignore warnings. That's a legitimate concern, most users are easily tricked, but that's not a vulnerability of SSL itself.

My assertion is that you can't just use SSL and leave it at that. In that case, you're only going to protect savvy users, and not even all of those.

That may or may not be true, but what is certain is that additional mucking around with salts, Javascript crypto, and protocols isn't going to improve the story you get with HTTPS.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.