Hacker News new | ask | show | jobs
by Someone1234 3818 days ago
You cannot hash passwords in a password manager. It has to be reversibly encrypted and turned back into plain text before utilisation.

So when people complain about password managers storing plain text (as opposed to hashing) they're barking up the wrong tree, it is a necessary evil.

You just want to see them encrypt those plain text passwords so that offline recovery is harder. That's what both Firefox's master password, CryptProtectData() for Chrome/IE, and the key-chain in OS X provide.

1 comments

I think you're trying to say something akin to but not quite "plaintext equivalent", and your terminology is mangling your argument.