Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The blog mentions, "We’re considering argon2 for our next upgrade". I suppose they could do in-line upgrades: as users are signing in, the SHA512 is piped through the old pipeline for verification and through the new pipeline for migration. As far as I can tell, there's no way for them to swap bcrypt out for argon2 using just their cold store.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: