3 ms·
> it's trivial to generate text that could match any given hash Actually I don't know why there is some hash used at all. According to the example, answers are
by meehow 7y ago
> it's trivial to generate text that could match any given hash
Actually I don't know why there is some hash used at all. According to the example, answers are stored in a session. CRC32 would do the job as well. Or no hashing at all. You would need some better hash in case when user downloads it. I can imagine different flow where you would need some better hash: I.e. you have some secret token, hash it together with captcha answer, send question with good hash to a browser and user sends back answer together with a hash he got. In such flow there would be no need to store values in a session.