Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Fun fact: Have I Been Pwned neither salts nor hashes the creds which it stores on its website, potentially making itself an interesting target for hackers[0]

[0]: http://risky.biz/RB388



HIBP doesn't store passwords, it only stores usernames and email addresses.


apologies, s/"creds"/"user data"


How exactly do you expect them to send an email to an address they only have a hash of?


HIBP hosts only completely Public alread leaked data -- that's how they source their data




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: