Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The password isn't leaked, a hash of the salted and peppered password is the only thing in the database (+ the salt, and the pepper elsewhere).


Assuming it's implemented that way. Which is a big assumption.


As the main post was written in the voice of a knowledgeable developer picking a login flow, I assumed so indeed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: