3 ms·
It is not required that your connection has been MITM'd. The service you are authenticating can accidentally log the plaintext password, they can store it with
by thinkharderdev 2y ago
It is not required that your connection has been MITM'd. The service you are authenticating can accidentally log the plaintext password, they can store it with an insufficiently secure hash function or not salt it. A malicious browser extension can scrape it directly from the input form. Etc, etc, etc.
Passwords are reasonably secure since we've been using them for a long time but there is in fact a huge chain of trust required to keep them secure and links in that chain frequently break.
- aragilar 2y agoIf the service is like that, then I'm not sure being able to log in as you is a major issue...