Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Agreed, you don't want to log passwords. But that's not unique to server generated passwords, you also need to avoid logging user generated passwords as well.

I'd recommend storing server generated passwords in the same way a user generated password should be stored on the backend: bcrypt or scrypt.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: