4 ms·
Aren't passwords hashed on the client side before sending it across the network? That would make your way around not work (unless that's done on the client side
by wapz 9y ago
Aren't passwords hashed on the client side before sending it across the network? That would make your way around not work (unless that's done on the client side also after verifying from the server that it's correct).
- rypskar 9y agoHashing it on the client side will make the hash the password. So the stored hash can be used as password by turning off the client side hashing, for instance by turning off javascript. You use https to avoid sending the password in cleartext over the network
- matthewmacleod 9y agoI've certainly never encountered a web app that hashes locally before sending. I suppose it could work if this was at the account creation or password management stages, but you couldn't implement it at the login stage for obvious reasons. I'm having trouble imagining what scenario client-side hashing would protect against.
- consp 9y agoMan in the middle attacks fetching for plaintext passwords -- edit: using a KDF would improve it even more.