Hacker News new | ask | show | jobs
by baddox 5133 days ago
Why isn't that technique (normalizing then hashing) acceptable? There is always a compromise between user experience and security. Why allow three character passwords, or passwords of "password", but not case insensitive passwords?