this post was submitted on 21 Feb 2026
430 points (100.0% liked)

People Mastodon

355 readers
13 users here now

People tooting stuff. We allow toots from anyone and are platform agnostic (Mastodon, BlueSky, Twitter, Tumblr, FaceBook, Whatever)

founded 4 months ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[โ€“] Maxxie@piefed.blahaj.zone 2 points 1 day ago* (last edited 1 day ago) (1 children)

which part was wrong?

Because the hashing happens server-side, it still has access to the original data. Which is why I said

It can leak if the server is compromised or misconfigured

[โ€“] Nomad@infosec.pub 1 points 1 day ago

The hash for a password is not that secret. For a strong password it can't be used for anything bad really.