|
|
|
|
|
by bawolff
1214 days ago
|
|
> If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid Again - how would that possibly be a security vulnerability? Like, its a really interesting security adjacent bug, but clearly not a security issue. If the attacker has the ability to set a hash, they can just set the hash to a known password. |
|