Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I didn't say it was easy; it's usually pretty hard/expensive to do it right.

But there are known best practices, and it looks like those weren't followed (at the very least, have a good password policy and salt the goddammed passwords before hashing).

here are two examples of companies doing security right:

[1] http://blog.lastpass.com/2011/05/lastpass-security-notificat...

[2] http://arstechnica.com/gaming/news/2011/11/valve-confirms-st...



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: