4 ms·
That would mean that you trust the client completely to log somebody in. What's preventing somebody from bypassing the clientside bcrypt check? As long as the
by Rafert 8y ago
That would mean that you trust the client completely to log somebody in. What's preventing somebody from bypassing the clientside bcrypt check?
As long as the password is sent over a secure channels (TLS) and doesn't leak somewhere on the server (e.g. logs), sending it plaintext from the client is not where most password breaches come from. But stuff like https://en.wikipedia.org/wiki/Secure_Remote_Password_protocol https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco... would provide a solution for that.
- hartator 8y agoI meant both registration and sign in forms, hash the password in JS, so there is no way to bypass bcrypt?