Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No...they literally have the password you just entered. In plain text. They can change the case of that and compare against the DB hash twice. The entropy for someone trying to brute force the hashes directly is identical.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: