Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If the site has control over my money or my public persona, then I very much need to care how they handle my password.

It is not uncommon for databases to be stolen via lost laptops, human error, or sloppy security. When this happens, I would prefer that the database not contain my plaintext password.

If someone obtains my password through such a leak, it won't help me that I've used a distinct password for that website.

It's bad news when a bank leaks their customer list. It's catastrophic news when a bank leaks their customer passwords.

If you don't store the passwords in the first place, they can't be leaked.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: