3 ms·
I believe they are referencing the fact that upon a login attempt the server does receive a plaintext password per se. Usually it is stored in memory only long
by born2discover 4y ago
I believe they are referencing the fact that upon a login attempt the server does receive a plaintext password per se.
Usually it is stored in memory only long enough to compare it to the hashed version from the persistence layer but... that's in theory.
- tuwtuwtuwtuw 4y agoWhen it comes to memory then it will typically be stored longer than necessary due to how garbage collection works in 99% of all of web applications.