Hacker News new | ask | show | jobs
by eurasiantiger 1852 days ago
The application has a much larger attack surface than the auth/user system, so it makes sense to store PII separately.