3 ms·
It's not ideal to send every new user's password to a 3rd party service.
by lancefisher 9y ago
It's not ideal to send every new user's password to a 3rd party service.
- Piskvorrr 9y agoHence the downloadable file, and even a suggestion to use that as an in-house checker. It's in the article.
- edelans 9y agoyou can still send the SHA1
- wongarsu 9y agoWithout salt, meaning the majority of passwords can be reversed with brute-forcing or rainbow tables. The second google result for rainbow tables lets me download software and tables to efficiently reverse any sha1 whos plaintext fits [a-zA-Z0-9]{1,9} or [a-z0-9]{1,10}. That's likely the majority of passwords an attacker would observe