3 ms·
Technically yes, but I would imagine they'd subsequently hash the hash on the server side as well. I assume the extra client-side hashing is done to keep the p
by EvanDotPro 11y ago
Technically yes, but I would imagine they'd subsequently hash the hash on the server side as well.
I assume the extra client-side hashing is done to keep the plaintext passwords out of the application memory, not protect it in transit.
To clarify, this is just an assumption. I have not read up on the topic nor do I claim to be a security expert. This is just what came to mind when I had the same thought as you.
Anyone else know for sure?