Hacker News new | past | comments | ask | show | jobs | submit login

I guess the logic here was as follows:

It's not good to send clear text user password to yet another system

-> send it hashed

But full hash might still be vulnerable to the rainbow table attack

-> let's use only a part of the hash, AND, reject full hashes.

In summary, I believe, they tried to avoid creating more ways in which user passwords could be leaked.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: