Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sounds to me like it'd be better to encourage people to pick longer passphrases (8 - 10 words instead of 4), in addition to using scrypt.


All you really need is to always prepend your username to your password. If people all did that, then 99.9%+ of these brainwallet thefts would already not have happened. Slow KDFs are just icing on the cake.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: