17.10.2016, 00:18
Quote:
If the server owner doesn't hash passwords and saves them in the database unhashed, are hackers able to just read the password?
If yes, why would they bother to find your password to log into your account and change data? They have direct access to your database and if they can see the unhashed password, they can also see the other data and change it without even logging in. Even when the passwords are hashed and they need to brute-force decode the password to see which password would match "drg8512gsgdrg5dr6sa4f8" (hashed password, which they took from your database), what would they need it for? They can see the hashed password so they can see the data as well, which usually isn't encoded in any way (money, score, kills, ...). |