TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Credential Node password hashing lib needs experts

2 pointsby ericelliottover 10 years ago

1 comment

shawndumasover 10 years ago
from the link: &quot;I want to make sure that the Node &#x2F; io community has a password security library they can trust. In 2013, I researched all of the libs I could find and found serious security flaws in all of them. I know it&#x27;s impossible to make it perfect, but we need to ensure that there is something that at least raises the bar enough that a random script kiddie can&#x27;t cause multi-million dollar disaster, PR nightmares, and personal loss to users.<p>I&#x27;m not a password security expert. I&#x27;m asking for your help. This has already been reviewed by many security experts, but I know there is room for improvement, and I want to make sure that users have a clear indication about which library author they can count on to really work to make their users more secure. Please review this code carefully. Attack it with everything you&#x27;ve got, and then file issues here. I&#x27;ll give you public credit, and you&#x27;ll be helping millions of people have a more security online profile.&quot;