|
|
|
|
|
by ihodes
5645 days ago
|
|
You missed that you're not going to be using the same password for each website. Autho.me isn't a spin-off of OpenID, it's basically outsourcing signing-in/password "storing" for websites that don't want to risk fucking it up. The point isn't to have a single ID to use across all websites. |
|
http://codahale.com/how-to-safely-store-a-password/
Not that it's Zed's fault that this is true†, but it's actually harder to safely host something like AUTHO.ME on a website than it is to simply use a reasonable hashing algorithm.
† I both believe this and also have to say it to avoid a sharks/jets rumble with him on HN.