|
|
|
|
|
by mjal
2210 days ago
|
|
That doesn't have to be the case at all. They could send the password (plaintext, hashed or otherwise) elsewhere to get checked that just takes a little bit of time, and get some form of positive/negative response back. Or any number of similar alternatives. It's still bad, but let's not jump to conclusions. |
|