Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

[deleted]


If the database record says the user hasn't changed their password, split the given password in half, check that both halves are equal to each other, and check that one half matches the hash of the password.


check that it's a string of the right form (e.g. it repeats something exactly twice) and then derive the original password from that, before feeding it to your hashing function.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: