Hacker News new | past | comments | ask | show | jobs | submit login

Is there a reason why in all of these compromises that they never state the type of encryption used on passwords?



Because somewhere between 97% and 100% of the recipients of the message would only be confused by that information.


Confusion, when followed by positive words, can make people happier sometimes. (Wow, I sure am glad they are so smart!)

I don't really see a big drawback to inserting a few extra words, if those words might get reputable people to say that the bad thing that just happened wasn't really so bad.


It seems more likely that they don't realize it's even important until they get hammered for details on what they used. Some PR person asks an engineer and he says "Yeah, it's fine, we hash/encrypt the passwords.." and only after they eventually disclose what they were using and have it explained to them do they realize they screwed up.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: