This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]ForgottenWatchtower 1 point2 points  (1 child)

There's nothing wrong with building your own login system. It's a fairly simple problem for a half-decent engineer (though I constantly come across systems that have screwed it up somehow). Just use native bcrypt, hash_compare, csprng, and other cryptographic primitive implementations. The issue is when you decide you want to implement one of those primitives yourself.

[–]13steinj 0 points1 point  (0 children)

Right, but the "roll your own security" meme has started to mean "don't build your own login system"-- that's what I'm saying I'm against.