You could extend this by storing the hash of all 3-letter combinations of the password on entry. Then ask for a random combination of 3-letters.
You could extend this by storing the hash of all 3-letter combinations of the password on entry. Then ask for a random combination of 3-letters.
The question is not whether on a technical level something got hashed. The question is whether a hash protects the password against brute forcing. And the answer is no.
Store in DB id position hash user_id 1 0 x0 1 2 1 x1 1 3 2 x2 1
Why do hacker news people think they are better at security than multi billion dollar banks?
Many banks (I work for one of them) follow reasonable best practices, allow or require strong passwords, store them safely and require sensible second security factors. Others are decades behind in security, using nonsensical security schemes like the ones morgante and mng2 described above or requiring your password to be letters and numbers only between 6 to 8 characters.
If you care about security, stick with the banks who do as well. Make sure their password guidelines are in order, go with the ones that make you use a second factor, and if you ever see any hints they're storing your password in plain text, run.
Banks are good at not losing money.
But website security is an afterthought for them.
It's easy to make a website that has better security practices than a typical bank website.
It's not about having better skills or resources, it's about having the motivation to do it in the first place.
A bank could set up spectacular security, but that doesn't mean they usually do so.
Everybody knows that we are hopeless at it, and often the flaws that are exploited are just as simple as this.