Hacker News new | ask | show | jobs
by matheist 3728 days ago
Please please PLEASE authenticate over https.

Currently you're just SHA512'ing your users' passwords and sending the hash over the wire in the clear. This is INCREDIBLY insecure and you're putting your users at risk.

I don't know a good resource off the top of my head to best practices, could someone else provide a link?

1 comments

Thanks. We will get it fixed.
Thank you!

Looks like a great idea and I will definitely check it out.

Cool. Let me know if you have any questions/comments as you do.