Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It shouldn't be possible to leak passwords, they should be hashed before being stored in the db surely...?


The very first line of the link lists

  user information (specifically, user email addresses,
  password hashes, session tokens, and last login timestamp)
So .. yes. Of course.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: