4 ms·
How is it at all like building a bank without locks? It jeopardizes users who reuse passwords which has been a security faux pas since passwords. I feel like pe
by boodrizz 9y ago
How is it at all like building a bank without locks? It jeopardizes users who reuse passwords which has been a security faux pas since passwords. I feel like people dwell on this pattern of hashing passwords to show off that they know what hashing is. In the age of weekly leaks and multi gig dictionaries, assume your password is in a dictionary if not really long, high entropy, and unique to that site. Even the "gotcha" xss someone demonstrated on T-Mobiles site has nothing to do with this. If somebody has every password, they won. If they have your hash table, they still won. Yes, passwords would have to be changed site-wide, but you'd want to do that either way. At least since it's a phone company, they would know how to reach you. It's embarrassing to see another post of developers harassing a social media pr person.
- MR4D 9y agoBecause it’s a minimum level of due care. Not meeting a minimum level is called negligence. I think most people would agree that in this day in age, leaving passwords in plain text is like not even making the effort. If you didn’t lock the doors on a bank, that would be the same thing - not making an effort, even though many criminals can pick a lock. So yes, the analogy holds up.