TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Microsoft SQL Server uses unencrypted passwords

3 pointsby maxtardiveau2over 3 years ago

1 comment

josephcsibleover 3 years ago
Wow, what a nothingburger. First of all, the passwords are hashed on disk; this is just about their transmission over the network (where they can't be hashed without the hash being password-equivalent). Anyway, the headline is only true if you don't count TLS as encryption, which is absurd. Yes, we'd probably be better off using some sort of PAKE protocol, but SQL Server handles passwords the same way basically every other server of any sort handles them. If this were actually a vulnerability in SQL Server, then you could count on one hand the number of services today that accept passwords but weren't also vulnerable.
评论 #30371522 未加载