Skip to content

Comment on Microsoft mishandling example.comparent

Comments

I don't think there's any evidence that windows sends cleartext passwords. The whole reason why NTLM is a thing is to avoid sending cleartext passwords.

Outlook appears to be

The 'https://' disagrees with your 'sending clear text passwords' statement.

It’s clear text to the receiving server, which is what we’re talking about, not one way hashed.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.