|
|
|
|
|
by madsbuch
1214 days ago
|
|
> If the attacker has the ability to set a hash, they can just set the hash to a known password. That requires the attacker top also have access to the salt I smell an underlying sentiment of "if the attacker has access to the DB, then it is broken anyways". This is not entirely true. Think a gateway service that lets the user to something on another service with access without access to the database immediately giving access to the system. This is definitely a security bug. |
|