Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Nope. They just store your 6-8 character password in plaintext behind their huge monolithic Java/.Net/Cobol app.


They employ a clever 3-step hashing algorithm, though:

    1. Truncate user's password to 8 characters
    2. Uppercase the entire thing
    3. Convert to EBCDIC




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: