4 ms·
Really, any password hash `PH(m,p)` can have server-relief by adding a regular cryptographic hash function `H` and making H∘PH your hash function. By this, you
by fryguy 11y ago
Really, any password hash `PH(m,p)` can have server-relief by adding a regular cryptographic hash function `H` and making H∘PH your hash function. By this, you store `p||H(PH(m,p))` in the database, and have the client compute `PH(m,p)` and send it to the server rather than sending the password `p`. You still have to send the salting information to the client though or use .
I don't see the server relief in Argon2's latest specification document though.
- creshal 11y agoI.E., cram-md5 and related password schemes. It's a shame it fell out of favour, I'd sure prefer something like this over sending plain text passwords via TLS…
- fryguy 11y agoIdeally we eventually get rid of passwords and use secret/private keypairs in the browser, or have some browser-based SRP.