4 ms·
That would destroy security, since a compromised server could now get your password by serving malicious JavaScript...
by devit 11y ago
That would destroy security, since a compromised server could now get your password by serving malicious JavaScript...
- jonknee 11y agoCan't a compromised server already get your password by serving malicious JavaScript?
- Stefan-H 11y agoA malicious server doesn't need malicious javascript to do it, it already receives the password in the plain, but that is what is trying to be mitigated in these efforts.
- jonknee 11y agoI was thinking a malicious 3rd party JS (say a CDN copy of jQuery or something).
- k3d3 11y agoYou might find interest in https://hacks.mozilla.org/2015/09/subresource-integrity-in-firefox-43/ https://hacks.mozilla.org/2015/09/subresource-integrity-in-f...
- jessaustin 11y agoSo you agree that a js lib would be an improvement over the status quo?
- Stefan-H 11y agoUsing a JS lib would not mitigate any risk here unless the compromising of the server that hosts the JS is separate from the compromsing of your web server.
- k3d3 11y agoIt mitigates passive MITM attacks, for one. On the other hand, there's nothing that's made _worse_ by choosing to do it that way. Plenty of things that are the same, some things better, but nothing worse.
- Stefan-H 11y agoHardly - if you are not using HTTPS in the first place then sending the hash across the wire instead of the password are the least of your worries.