Hacker News new | past | comments | ask | show | jobs | submit login

You are correct and I was sloppy in explaining it properly.

In general however, I believe that there is no inherit advantage of certificates over passwords, except for the key-size obviously. Everything else is just convention/standards.

Please see the following page that explains better what I meant when I said that the password should be hashed: https://en.wikipedia.org/wiki/Hash_chain

Using such a mechanism (including salts / challenges) will prevent an attacker using the hash as the password.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: