Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why aren't these sites storing salted hashes? Plain text passwords are bad news...


Where did you get that impression? Not from the linked-to article, from my reading of it.


If a site is storing hashed passwords with salts, you generally don't know what the user's password is and you can't unhash them to find out.


Right, and what does that have to do with this article about lists obtained by phishing and the like?


My mistake, I thought these passwords came straight from the databases.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: