Hacker News new | ask | show | jobs
by aobdev 1360 days ago
They’re talking specifically about client-side hashing. You’re right that the system will hash the stolen hash, but only in cases where the system can’t be bypassed (which client side code always can be).