Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, most users wouldn't understand what this is. However, if some did, and they expected it to be there, that might be enough.

You're quite right that there'd be nothing stopping people from using this dishonestly, except their consciences and the fact they may have some explaining to do if a dump of MD5s of their passwords was released. That may or may not be enough.

In any case, I'm sure that this industry can do a bit better than it is at the moment. With big breaches of LinkedIn, Last.fm and eHarmony in the last 48 hours, surely something can be done.



The problem is that the people who don't use a KDF don't know any better. Aren't these the same sort of people who will implement the same logo as other sites use without understanding what it means?

> except their consciences

I would add ignorance to that list.


Like what? The other guy was nice, but badges are flatly stupid. Unless you want to force websites to allow security inspectors, you have to either assume they're doing the right thing or believe them if they tell you "They've got it".




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: