4 ms·
It mitigates passive MITM attacks, for one. On the other hand, there's nothing that's made _worse_ by choosing to do it that way. Plenty of things that are the
by k3d3 11y ago
It mitigates passive MITM attacks, for one.
On the other hand, there's nothing that's made _worse_ by choosing to do it that way. Plenty of things that are the same, some things better, but nothing worse.
- Stefan-H 11y agoHardly - if you are not using HTTPS in the first place then sending the hash across the wire instead of the password are the least of your worries.