Oct. 25, 2022, 4:36 a.m. | /u/CryptoSeb

cybersecurity www.reddit.com

Would you consider it bad practice for a website that allows user registration to explain how passwords are hashed in the security section of the FAQs?


In a debate with a friend who says, "Only password managers ever tell you what algorithm they use to hash your password. I've never once noticed it on any other type of website and it would be Hollywood to do this."


Is there anything wrong with outright stating that the site uses argon2id (or …

bad cybersecurity practice transparency

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Senior Manager, Security Compliance (Customer Trust)

@ Box | Tokyo

Cyber Security Engineering Specialist

@ SITEC Consulting | St. Louis, MO, USA 63101

Technical Security Analyst

@ Spire Healthcare | United Kingdom

Embedded Threat Intelligence Team Account Manager

@ Sibylline Ltd | Austin, Texas, United States

Bank Protection Security Officer

@ Allied Universal | Portland, OR, United States