Hacker News new | ask | show | jobs
[S5 Slides] Security in Web Applications (6.470.scripts.mit.edu)
16 points by costan 5998 days ago
3 comments

1) Don't use anything fast (like md5) to hash your passwords. Use many-rounds of md5 or sha-1, or use something specifically designed for password hashing like eksblowfish

2) Don't escape your SQL, use parameterized queries

How good is md5 plus a 4-character (digits, actually, in the slides) salt?