Why should I care about hashing passwords anyway?

后端 未结 12 1005
南旧
南旧 2021-01-03 23:04

If a hacker has access to the hashes in my DB, he has access to the rest of the information in the DB anyways. So why would he bother trying to decrypt the passwords? Should

12条回答
  •  佛祖请我去吃肉
    2021-01-03 23:11

    If an application is to show grade information at the university then having access to the password will allow you to get the grades for that person. If the password also allows you to log into the online course system then you can submit tests as that user.

    If the data is even more sensitive, such as credit card numbers or health records, you are open to lawsuits.

    Odds are that the more sensitive information may be on a more secured system, behind stronger firewalls, so they may have found a weakness by hacking into the authentication database.

    By hashing the password, then those that have access to the authentication database can't see the password and so log into the very sensitive system as a different user.

提交回复
热议问题