3 ms·
Don't see a mention of Pwdhash in the comments. That Firfox/Chrome extension would have protected you. https://www.pwdhash.com/ https://www.pwdhash.com/
by anonymous246 15y ago
Don't see a mention of Pwdhash in the comments. That Firfox/Chrome extension would have protected you. https://www.pwdhash.com/ https://www.pwdhash.com/
- Joakal 15y ago> Don't see a mention of Pwdhash in the comments. That Firfox/Chrome extension would have protected you. Your statement is misleading. That website is essentially creating a hashed password of the original password. But the target website will still consider it your password in which case it will not protect you once the 'password' to the website is known which the author is talking about. To put it another way, if your password is 'abc' and hashed it becomes: 'ABCDEFG'. The website stores it plaintext as 'ABCDEFG' to which a hacker has it. Then if anyone later accesses the website, they would be able to just type in 'ABCDEFG'. Pwdhash is just another form of a password manager.
- Johngibb 15y agoIf it incorporates the domain into the hash (which it sounds like it does), this is still useful. If a hacker gets you password 'abc', they can log into any other website for which you use the same password. If they get the hash 'ABCDEFG', they only get into that one site.
- anonymous246 15y agoOk, I see how my comment could have been misread. Here's my clarification: You need take a step back and think about why it is bad that your password is stored in cleartext: if there is a security breach at site X, your login credentials can be tried on many other sites. Since people tend to use the same login/password combo everywhere, your exposure is likely much larger than your info stored at site X. Which is why vandals/criminals covet password databases. You seem to be under the misapprehension that the risk is that somebody will search through your email archives (or while it is in transit) and sniff passwords. IMHO, that's a trivial risk. A tool like Pwdhash will ABSOLUTELY protect you against the "en masse password theft at website" sort of attack, which is the more serious threat.