Hacker News new | past | comments | ask | show | jobs | submit login

They probably do know, and practically speaking I would guess that those accounts using an older hash are those which nobody has logged into since they switched to bcrypt. Yeah, we don’t know for certain, but it’s a reasonable assumption.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: