3 ms·
Why not just lcase everything during initial hashing and later auth? sha1sum(lcase($passwd). $salt);
by fuzzix 14y ago
Why not just lcase everything during initial hashing and later auth?
sha1sum(lcase($passwd). $salt);
- deleted 14y ago[deleted]
- zerovox 14y agobecause as nostromo said then uppercase counts for nothing. Facebook only lets you log in if you accidentally use cap-lock or accidentally capitalize the first letter(quite common on phones). If you lowercased the whole password first, you reduce the benefit of having uppercase characters at all.
- fuzzix 14y agoAh, I missed that, sorry. I think the point stands for the Blizzard case - there seems to be an assumption in some corners that the password is stored plain text, but I would imagine case neutralised (so to speak) passwords are hashed.