3 ms·
One additional character may be for "I fatfingered a key as I pressed Enter". You don't need to store a second hash for any of these; just transform the sent p
by sonofgod 10y ago
One additional character may be for "I fatfingered a key as I pressed Enter".
You don't need to store a second hash for any of these; just transform the sent password with (invert all characters, invert one character, delete last character), rehash it and compare it to correct.
Whilst it does increase the numerator, it also allows Facebook to decrease the number of obviously wrong password attempts permitted before taking additional precautions. Since these are overwhelmingly likely to be user error, I think it's a perfectly reasonable tradeoff.