Hacker News new | ask | show | jobs
by gregjor 733 days ago
That's what I wrote -- sanitize before passing to the PHP password_hash function, which obviously happens on the server.