Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've always wondered this... So many organizations do this.


Typically compatibility with legacy systems


That shouldn't be a factor if passwords are hashed, right? In other words, you don't have plain-text to pass on to the legacy system.


I was once told it was to prevent DoS-ing the back end of the system by submitting gigabytes to hash...

the check was an HTML input limit and there was no backend limit...

I was sad.


Maybe the interface expects an 8 character password even if it's hashed on the backend. Maybe it's hashed by something that expects a certain length because it's using a silly algorithm. Maybe not all systems use hashed passwords. Hard to say from the outside, but in my experience it's usually not because the developers were stupid or ignorant.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: