4 ms·
The big problem of a service having your true password (instead of the hash of the password) is that many users use the same password for a multitude of service
by qpiox 8y ago
The big problem of a service having your true password (instead of the hash of the password) is that many users use the same password for a multitude of services (read Gmail, Hotmail, Yahoo, Amazon, ...)
So it's bad practice to keep or transfer the users cleartext password. It should never leave her browser/client. Period.
- javagram 8y agoPassword managers and service specific 2FA solve that problem quite nicely for now (edit: although yes most users aren’t willing to do that).
- aeorgnoieang 8y agoIf the service has only the hash of the password, then that's the password, which would then be subject to the same problems as a "cleartext password".