2026-03-25 06:52 UTC
Replies (1)
-
@riverpunk@defcon.social 2026-03-27 09:07
@stash @gregthemiller unfortunately I feel like using a hash function that gives the same result for similar looking input strings would kind of go against the entire point of a cryptographic hash, which is supposed to be chaotic and impossible to predict from one input to another without just running the function. Also curious to wonder on the more logistics side: when a site adds a new hash function, they get the hash by running the function on your password next time you log in. What if the password logs you in cuz it's a typo away? Then under the new hash, your typo away password doesn't hash the same as your original? You'd get locked out, or even worse, only locked out *occasionally*, when the other hash is used.