4 ms·
Given how common SSL interception is becoming, I don't consider TLS sufficient protection for passwords. Your security appliance may have a legitimate need to s
by gdavisson 8y ago
Given how common SSL interception is becoming, I don't consider TLS sufficient protection for passwords. Your security appliance may have a legitimate need to see my network traffic, but not my password. And if someone pwns the appliance, they pwn everything. Client-side hashing helps a little, but not enough; you're still vulnerable to pass-the-hash attacks. Using PAKE inside a TLS connection avoids all of these vulnerabilities.