Submission timeline
2007–2026One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.
First comments on top threads
HN comment orderIt is still just fine to keep using bcrypt, scrypt, and PBKDF2 --- but it wouldn't make much sense for them to have a Password Hashing Competition and not conclude it by recommending some algorithm over all the others. The real distinction isn't between apps that use the PHC winner and apps that use "legacy" password hashes, but instead between apps that use serious password hashes at all and apps that just use SHA hashes. Still: an interesting development!
"The poor state of passwords protection in web services: passwords are too often either stored in clear (these are the services that send you your password by email after hitting "I forgot my password"), or just hashed with a cryptographic hash function (like MD5 or SHA-1), which exposes users' passwords to efficient brute force cracking methods." If you can't get people to use current crypto hashing techniques like bcrypt or scrypt why would coming up with another one help? Of…
The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.
- Breakout years
- 2
- Total points
- 173
- Total comments
- 100
100+ points or 50+ comments
reference only — not used in Hall rules or ranking
reference only — not used in Hall rules or ranking
Every submission
| Date | Title as submitted | By | Points | Comments |
|---|---|---|---|---|
| 2013-02-14 | Password Hashing CompetitionFirst breakout | dchest | 49 | 73 |
| 2014-02-12 | Password Hashing Competition - new PBKDFs | ballard | 2 | 0 |
| 2015-11-02 | Argon2 Wins Password Hashing CompetitionBest thread · Latest 20+ point return | tptacek | 122 | 27 |
