Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Facebook must encrypt user passwords and regularly scan to detect whether any passwords are stored in plaintext; and

Why are they storing passwords at all? It's not necessary for authentication. They should only be storing a hash, or better yet a public key derived from the password on the client.



It came to light that they were storing passwords in plaintext in an application log. In theory they only store hashes in places where they actually intend to store passwords.


I think this refers to previous stories where there were reports of passwords being logged as part of what I assume was request parameter logging.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: