3 ms·
No, the server doesn't "know" the plaintext password, the server knows the hashed password and the salt. The plaintext password is in memory during your login r
by titaniczero 4y ago
No, the server doesn't "know" the plaintext password, the server knows the hashed password and the salt. The plaintext password is in memory during your login request's lifetime, once it is hashed and compared against the stored hashed password, the plaintext version no longer exists on the server.
Very different case from storing them in plain text in the database or elsewhere.
- VWWHFSfQ 4y agoIf the plaintext password traverses the server's memory space then yes it "knows" the plaintext password. A nefarious server administrator can do whatever they want with those plaintext passwords.
- lxgr 4y agoThere is a large difference in attack surface there, though: Passwords stored unhashed in a database fail catastrophically and irrevocably against a point-compromise attacker. Hashed passwords, validated using plaintext passwords, only leak all passwords entered since the moment of compromise.
- VWWHFSfQ 4y agoI'm certainly not denying that. But to try to claim that the server doesn't know the real password is completely false. Whether they hash/salt the stored value is completely irrelevant to the point that you have to trust the plaintext password handling end-to-end since the server can do anything it wants with your real password.
- stefs 4y agoit's not about nefarious server administrators, it's about an attacker getting in, dumping the database content, logs and whatever else they can grab. they then search those for valuable information they can sell - like email addresses, username+password combos, payment info, the likes. those are then bundled and sold on the darknet to spammers and phishers. if the credentials are in the logs they'll harvest those to attempt logins on other sites.