TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

My bank password is 'sort-of' hashed

8 点作者 mstockton大约 12 年前

4 条评论

tg3大约 12 年前
It should be noted that by also storing a hash of your password in keypad-compatible format (if you're right about this) is that it significantly reduces the search space for a potential brute force attack. It also seems they don't allow special characters, which is a further reduction. I'm not sure that a robo-caller is the most efficient way to steal a bank password, but it is certainly possible.<p>Of course, the cynic in me says that they are storing an encrypted, as opposed to hashed version of your password. But one can hope!
评论 #5410102 未加载
评论 #5410005 未加载
zck大约 12 年前
If you try to log into your bank with <i>PASSWORD</i> instead of <i>password</i>, does it work? They could be converting your password to numeric as a first step to using it for anything.
评论 #5410086 未加载
efutch大约 12 年前
They could be using some kind of format-preserving encryption, but then they would have needed an unhashed version of the password to generate this "phone input" field.
bochoh大约 12 年前
Very interesting.