3 ms·
Presumably if the passwords are hashed they have no way of telling you your password. They can only reset it. So yes, generally if they send you the password t
by fuzionmonkey 15y ago
Presumably if the passwords are hashed they have no way of telling you your password. They can only reset it.
So yes, generally if they send you the password then that means they store it in plain text. While it isn't always that hard to crack a password hash, it is unlikely that Amtrak went through that length to retrieve the password.
- latch 15y agoI think you proved my point. There's a 3rd option - they could be using a symmetric-key algorithm. This would make it trivial to decrypt for Amtrak - while difficult for anyone else to decrypt. The problem with this, and why people don't view it as much better than plain text, is because it's a single point of failure - and if your DB has been compromised, your secret keys (in a config or in source) probably isn't too far behind.