> Accepting the hash lets people with database access perform a real login if needed.
... and if anyone managed to say do an SQL injection and retrieve said hashes, then that then would give them access to your users accounts, right?
... and if anyone managed to say do an SQL injection and retrieve said hashes, then that then would give them access to your users accounts, right?
Without doing the OP's "trick" however, if you somehow managed to get a hashed and salted password then it still wouldn't be enough to gain access to someone's account.