Reply to post:

Twitter: No big deal, but everyone needs to change their password

teknopaul

I think its fairly common to send "plaintext" over ssl and hash and compare to stored hash during auth.

What would you recommend?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon