3 ms·
Wouldn't that make it easier for someone that has access to hashed passwords in the case of a database leak? They would just have to submit the username and the
by amhokies 8y ago
Wouldn't that make it easier for someone that has access to hashed passwords in the case of a database leak? They would just have to submit the username and the hashed password (which they now have).
- etruong42 8y agoYou're right, but the attacker won't get the user's original password that they probably reuse elsewhere. If it's just your authentication system hashes that are compromised, the damage can be contained.