Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are they sending the passwords or are they hashing and sending the hashes? I know 1Password's watchtower uses hashes to detect leaked passwords.


Almost certainly they're sending hashes. However, if they don't have a way to disable this, that's a serious problem, hashes or not.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: