Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think he was thinking of truncation by crypt, so that even passwords that are completely different (bar the first 8 chars, bar collisions) would match.


I think the point is, the user's password could potentially be set to something other than the original if they happen to type it "close enough". That would cause major confusion going forward.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: