Hacker News new | ask | show | jobs
by NavinF 1571 days ago
> Thoughts?

Honestly, I hate it.

Why select a few chars of the hash instead of using something like hash(argon2(password) + domain)

Anyway FIDO tokens and WebAuthn are the future. They do a better version of this in addition to eliminating phishing, replay attacks, etc.