Hacker News new | ask | show | jobs
by marcinzm 836 days ago
No...they literally have the password you just entered. In plain text. They can change the case of that and compare against the DB hash twice. The entropy for someone trying to brute force the hashes directly is identical.