Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
dec0dedab0de
on Sept 4, 2020
|
parent
|
context
|
favorite
| on:
We didn't encrypt your password, we hashed it
If that gets leaked the attacker could brute force that, and match the results to your entire list of hashes. If they're salted, they would still have to brute force each password individually.
dvt
on Sept 4, 2020
[–]
Totally agree with this, hence the caveat that the code doesn't get leaked/compromised :)
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: