Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah I guess the first.

I suppose they could insist on an online login before they allow an offline login, then save the hash locally. A bad person would need to generate a hash collision to login then.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: