I heard that they require plaintext data to work. What are the other factors to this?

  • sanzky@beehaw.org
    link
    fedilink
    arrow-up
    2
    ·
    2 days ago

    you ask the user for it if they want to recover the account and hash it. if the hash matches your previously stored hash then you send the email

    other providers that position themselves as secure for activists or journalists do exactly that and they cannot handle that information