3 ms·
> A hashed password cannot be stored, otherwise that hashed password becomes the plain text password anyway (essentially destroying any benefit hashing would ha
by mooneater 7y ago
> A hashed password cannot be stored, otherwise that hashed password becomes the plain text password anyway (essentially destroying any benefit hashing would have here).
The plaintext password may be re-used by the user on other systems, so yes hashing would still benefit here.
- wlesieutre 7y agoI think parent is saying you can't have a login system where you store the hashed password locally and then log in by sending the hashed password to the server. The hashing to validate a password has to happen on the server, otherwise anyone could get a copy of your hashed password and submit it as a login. But as other replies have pointed out, you can generate a login token to offer a "save password" feature without actually saving the password to disk.