Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is it completely beyond the bounds of possibility that they're storing the password as originally entered (salted & hashed), but trying all combinations of upper / lower case at login-time (only after the entered password fails)? It would only be for a small subset of logins, and for the majority of passwords, a manageable number of combinations (2^num-alpha-chars-in-passwd). I believe Facebook do something similar.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: