Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That begs the question: are they truncating the password string before hashing it ... or truncating it and saving it plaintext?

I don't understand enforcing a max password length when the password should be stored as a hash.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: