Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It gives some level of protection against buggy server-side code leaking the plain-text password. I remember a case where a site logged all request information (including the plain-text password) directly to a log file. Oops!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: