Hacker News new | past | comments | ask | show | jobs | submit login

You could salt the LSH with a different per-user salt.



True, if you were only concerned about similarity with the same user's passwords.


which in this case we are. We don't want to reject a password because it is similar to some other user password.

Mind, I think the feature is misguided, but it is probably possible to implement it safely.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: