Skip to content

Comment on On cryptography and dogmasparent

Comments

That's vulnerable to a length extension attack: sha1(passwd|am) can be used to derive sha1(passwd|amazon). (See Wikipedia for a discussion.)

Don't try to get clever, just use random passwords.

Thank you so much! It is exactly what I was looking for.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.