So they are storing length and hashes of subsets of the password?
You could brute force a subset of 4-5 characters way easier than a 20 characters password.
How is this secure? Anyone care to explain how this adds security?
You could brute force a subset of 4-5 characters way easier than a 20 characters password.
How is this secure? Anyone care to explain how this adds security?