4 ms·
They will just check your password against a list of 'bad' passwords when you log in. No need to brute force the stored hash.
by jarito 14y ago
They will just check your password against a list of 'bad' passwords when you log in. No need to brute force the stored hash.
- wizardishungry 14y agoObviously that would work, but not if you're using Challenge-response authentication. In general, I don't think people bother with now that when using https.
- wizardishungry 14y agoA little bit of googling makes it seem like auth tokens are not sent it plaintext over HTTPS but are authenticated using challenge response – http://forums.dropbox.com/topic.php?id=47952 http://forums.dropbox.com/topic.php?id=47952 The WWW site may differ.