Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes fair point.

But hashing the other data isnt practical - so it's the security vs. access tradeoff. You can hash passwords without much inconvenience.

Also with individual pieces of those other examples of data you mention it is not possible to gain access to the rest. Whereas with a password it IS. Damage limitation.

Finally the password and username (or email) are "front of the line". They HAVE to be accessible to an unauthorised client simply so said client can be authorised. Whereas the other data should require authorisation to access.



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: