Hacker News new | past | comments | ask | show | jobs | submit login

"In some cases, we may require you to change your password. (For example, if it’s commonly used or hasn’t been changed in a long time)"

Commonly used? What do they mean by that? Aren't they supposed not to know my password?




Good question, but perhaps it's shorthand for "your password generates a hash matching that generated by passwords found in various stolen password lists in circulation".


In which case they're not hashing the password properly, they're likely checking the plaintext password as it's sent over HTTPS.


They do not need to transmit plaintext passwords, they merely need to pick when and how to salt each password carefully.

What they can't do is randomly salt each stored password.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: