Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That may be, but even if PCI doesn't require you to have the passwords unrecoverable, I'm pretty sure that transferring all of them in bulk to someone else via email should violate some part of PCI. Even if that person is an auditor. The potential for abuse is too high.


Transferring them in bulk wouldn't technically be against any of the rules. There are provisions that access to bulk data be limited to those that 'need' it. This is obviously ambiguous and up to interpretation of your auditor. In this case, since the auditor is asking for the data, one would assume they see no issue with it.

Typically communication of secure information to the auditor would need to be encrypted so there is little to worry in terms of a mail administrator having access to the list.

Remember, PCI very frequently ignores practical reality and common sense.


Actually, hashed password ARE recoverable, technically. Though it would take a VERY long time to brute force the original passwords.


In theory, there are infinitely many passwords that map to the same hash, so not all passwords are recoverable. In practice most passwords will be recoverable (given enough computing power), because there will only be a single 'reasonable' match (you will probably find only one for passwords of reasonable length).


But would you consider that 'recovery' or 'discovery'. To me, recovering passwords means applying an operation to reverse encryption. Brute-forcing passwords is simply guessing, which makes it a discovery.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: