• coffee_tacos@mander.xyz
    link
    fedilink
    arrow-up
    0
    ·
    20 hours ago

    They better not know whether the old password matches their new password requirements, as all they should have is the salted hash of the password, which reveals no information about the password on its own.