Comment on A New, Simple Way to Salt your HashesparentComments−stcredzero18yMy assertion is that you can't just use SSL and leave it at that. In that case, you're only going to protect savvy users, and not even all of those.−tptacek18yThat may or may not be true, but what is certain is that additional mucking around with salts, Javascript crypto, and protocols isn't going to improve the story you get with HTTPS.
Comments
My assertion is that you can't just use SSL and leave it at that. In that case, you're only going to protect savvy users, and not even all of those.
That may or may not be true, but what is certain is that additional mucking around with salts, Javascript crypto, and protocols isn't going to improve the story you get with HTTPS.