• abhibeckert@lemmy.world
    link
    fedilink
    English
    arrow-up
    50
    arrow-down
    2
    ·
    edit-2
    11 months ago

    The website should feed your password straight into a well known hashing algorithm or key derivation function that has undergone a decade or more of careful scrutiny, without any other processing. The output will usually be a fixed length base64 or hex string.

    There’s a short list of about three options that are currently considered acceptable, and a few more are probably fine but are a little too easy to crack these days (e.g. anything that shares the same math as bitcoin… what if someone throws a mining datacentre at your password?)

    If the site breaks, maybe you don’t to be a customer of that service.

    • Vilian@lemmy.ca
      link
      fedilink
      English
      arrow-up
      8
      ·
      11 months ago

      make one account with emoji password to test their system, if it break, good, go create hour account somewhere else