Hacker News new | ask | show | jobs
by tragicpapercut 2529 days ago
This is why you shouldn't "innovate" with encryption unless you are a trained cryptographer (or equivalent). Cryptographers may be programmers, but programmers are not cryptographers.
1 comments

You don't need to be a cryptographer to know that you don't do plaintext passwords.
But it seems it wasn't obvious to bullen that this way the password is essentially sent in plain text. So yes, let your authentication be analyzed by an expert or use standard software.
to state the obvious: there are other things you don't do