Hacker News new | ask | show | jobs
by tempestn 3697 days ago
Ahh thanks. I read the email they sent out, which had very similar content, but omitted that bit. Just skimmed the post itself, but obviously missed that key info.

Interesting that they don't include strengthening their encryption (ok, hashing) in the list of steps they plan to take, but presumably they will.

1 comments

From the same incident report: When users reset their password, we’re going to be hashing it with the bcrypt algorithm with a strong cost value.
My god, I swear they're ninja editing the thing on me! I'm really not normally someone to comment before RTFA. Thanks for patiently leading me through it. :P