4 ms·
You're still passing the output to the server, which can be repeated. Certainly better than just a password, but not as good as public key crypto. In the end,
by ybx 11y ago
You're still passing the output to the server, which can be repeated. Certainly better than just a password, but not as good as public key crypto.
In the end, I'd probably prefer something like SRP
- deleted 11y ago[deleted]
- imaginenore 11y ago> You're still passing the output to the server, which can be repeated. Not if the server generates a unique ID for each attempt, and that ID must be used in hashing. It can be as simple as a timestamp.
- k3d3 11y agoWhich is then going beyond just using scrypt on the client. What you explain is simply challenge-response authentication.