2 ms·
Ah answered elsewhere, if the client sends the hash and you log the hash then you still have a problem. The user should change passwords. Although I think this
by tada-ssola 8y ago
Ah answered elsewhere, if the client sends the hash and you log the hash then you still have a problem. The user should change passwords.
Although I think this still improves the situation if the password is reused. I.E. I can't use the logged hashed password on other sites.