Hacker News new | ask | show | jobs
by whatevaa 3061 days ago
Still better than no hashing. Still a tough nut to crack if it's hashed plus salted with unique salt.
1 comments

Ugh. It's supposed to be Best Practices, rather than better than nothing, and is ostensibly from Google. So should be limiting to the appropriate choices: bcrypt, scrypt, PBKDF2 or Argon2.
Something they acknowledge later with SMS being a bad idea, but may be the best option for a specific workflow.
Not everyone can used the last hype algorithm, whether because of library support, regulations or technical constraints.
bcrypt is old enough to vote this year
still can't drink in US though