82 karma · joined May 23, 2012
Sarcasm aside, your comment is useless. I think that there is still significant ambiguity in the sentence as written as you parent comment does. It is only saved by the fact that after the "and" is "two onlookers", allowing the reader to make logical sense of the sentence, but it still holds ambiguity.
EDIT:
You also described Public key cryptography as having "2 different keys. One allows for encryption and the other for decryption. In this case, the decryption key is public so everyone can decrypt." This misses the mark a little bit. The public key could be used to encrypt as well, so that only the holder of the private key can read the information. Using the private key to encrypt is generally used in digital signatures so that the recipient can verify that the sender is who they claim to be. This scenario doesn't attempt to keep the data secret, because anyone with access to the public key can decrypt the data.
None of what you assume a "fuck 'em" mentality means is suggested in this article. It doesn't say that you should go out and walk across the country, it simply asks "what if?". It tells you to consider other options, to do much of what you suggest in the last paragraph of your response, except in your response you still have the assumption that to be successful in life, one must "care about your success in the company (and in your career)".
This article to me is a reminder that I don't need to do what everyone else is doing, or expects me to do, in order to be happy. I need to do what makes me happy, in order to be happy. Sometimes those values align, sometimes they don't. And in the instances that they don't, if someone else has a problem with that - Fuck 'em!
Stack overflow on the other hand is for people to:
[A]sk practical, answerable questions based on actual problems that you face. Chatty, open-ended questions diminish the usefulness of our site and push other questions off the front page.
"I guess my point is, that if you want to become a programmer, you have to be comfortable with having to learn new things constantly for the rest of your life."
I really feel like this is the outlook everyone should take on life, not just programmers. Maybe the causality ought to be switched; good programmers are people who have a "learn something new every day" outlook on life. Hell, it could even be said that good people in any field are those who take that viewpoint on life.
I like the method that link provided, but there are some drawbacks, needing to update every user record with a new hash (offline process) - this is almost guaranteed to require taking the site down, which most people do not like to do. This is because you can't have some users with the old hashing process ,and some with the new.
Additionally, each salt is still unique per password, so the attacker would need to generate a full dictionary per record that they want to crack - generally not worth it.
"when it's easy to retrofit later" - I think this is the key part of your statement. When is it easy to retrofit later? You then have to pick your poison:
1. Switch entire system over to new hashing function - reset all user's passwords 2. Add in interoperability of hashing functions - what I'm suggesting you do from the beginning, making it much easier to do.
Number 1 is a horrible user experience, number 2 is much easier to do from the onset.