this post was submitted on 17 Dec 2025
22 points (100.0% liked)
Explain Like I'm Five
19238 readers
49 users here now
Simplifying Complexity, One Answer at a Time!
Rules
- Be respectful and inclusive.
- No harassment, hate speech, or trolling.
- Engage in constructive discussions.
- Share relevant content.
- Follow guidelines and moderators' instructions.
- Use appropriate language and tone.
- Report violations.
- Foster a continuous learning environment.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Because the service is going to hash whatever password you provide. If you sent the hash itself, it would hash it again and get a non-matching result.
You'd think that having those hashed values might help, but it doesn't really (as long as other best practices are in place). Ultimately having someone's password is used to impersonate them, which means using the same front end to the service as everyone else.