3 ms·
I can't think of any security implications of hashing on the client-side. What's your thinking?
by libeclipse 10y ago
I can't think of any security implications of hashing on the client-side. What's your thinking?
- fnordsensei 10y agoDoes salting work if you hash in the browser?
- libeclipse 10y agoWell in this case the hash would be passed to Bcrypt or Scrypt, which have built in salt support, so client side salting wouldn't matter.
- shawnz 10y agoIf the hashes are leaked, you could log in with them.
- XorNot 10y agoWell serverside you store them as plaintext equivalents - i.e. salt+hash the hash. So a leak doesn't leak the user-side.