3 ms·
But the password is only known to the client?
by deepbreath 8y ago
But the password is only known to the client?
- mehrdadn 8y agoOnly if the server only keeps around the hash -- which is why I said there are trade-offs to be made. The point I was making was that the mere fact that you're sending a hash does not trigger the "hash-becomes-password" issue; that's a result of secondary constraints imposed on the problem.