"in the clear over ssl instead of hashing them"? am i missing something here?
is ssl insecure? is there some way to charge a credit card that doesn't actually involve sending the number to anybody?
I didn't realize that the HN login page didn't send a password on a login.