Hacker News new | ask | show | jobs
by etruong42 2964 days ago
You're right, but the attacker won't get the user's original password that they probably reuse elsewhere.

If it's just your authentication system hashes that are compromised, the damage can be contained.