TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Do You Disclose Your Password Encryption Policy to Users

1 点作者 _nate_大约 11 年前
I haven’t come across any real discussions about this, so I thought I would ask: Do you think it’s a good idea to disclose your password encryption policies in your privacy policy or terms of service agreement? In other words, would you tell your users - and the world - you don’t store their passwords in plain text, and disclose the exact method you use to store passwords?<p>For example, a privacy policy might read like this;<p>“Under no circumstances will we store your password as plain text. All passwords are encrypted with the Bcrypt hashing function and individual random password salts. If your password is 123456, your password would be stored in our database in a form similar to; salt:f11ba67d8a hash:$2a$08$jRAovt7x1lgHjMGsZstzUukaE4Nga6jxfneZXPSMc6&#x2F;Uhlx.rY4ri Therefore, our website - nor anyone else - will know your your password.”<p>Question #1: Do you think publicly disclosing password hashing is a good policy?<p>Question #2: Would disclosing password hashing policies disincentivise hackers from attempting to hack your password database?<p>PS: This is not a question about which password hashing scheme or use of salts is best.

1 comment

_nate_大约 11 年前
Also, are there any examples of companies &#x2F; websites who publicly disclose their password encryption policies on their sites &#x2F; apps?