Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It reduces the keyspace that needs to be searched when bruteforcing... leading to accounts being compromised more easily. That's about it.


At the same time, I think it's just a really quick/lazy way to prevent SQL injection.


well you have already lost if you try to insert the password into the database without applying a salted hash function on it.


Don't most "web" languages support parameters in the same was .NET does (at least with Sql Server)?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: