Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If the hashes are leaked, you could log in with them.


Well serverside you store them as plaintext equivalents - i.e. salt+hash the hash. So a leak doesn't leak the user-side.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: