Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Isn't there a security concern in exposing the username of who you share a password with?

Yes, because now you know their password. Which is bad.

It also means if you want to bruteforce something, you dont have to bruteforce every account separately.

Last of all, to even implement that you would need to be storing the passwords unsalted in the db, which is huge no-no.

In any case, this is an article about bad practises, but the first screenshot was fake according to the text.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: