Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I thought that a while ago but then someone just pointed out that you bcrypt hash the MD5 hash and support two step (MD5 then bcrypt) until they login at which point you can rehash using only bcrypt.


That's a much smarter approach. Never thought of that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: