Hacker News new | ask | show | jobs
by Amorymeltzer 3108 days ago
Why not just use a longer salt? The username is only going to reduce randomness. Moreover, I don't buy the presumed advantage: nobody is really parsing that message to mean someone else could have the same password.