Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Even if saving database space is a concern, you could store a truncated password hash.


If you don't use the full hash, I believe you can't really make any guarantees about the variance and distribution of characters in the hash. So not sure that's such a good idea.


If you'll go as far as saving a truncated hash, it's better to just save the whole thing. I don't see any good reasons not to.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: