3 ms·
Yes we should be hashing to avoid these sort of password logging issues. This is one of those old internet tech-debt that should be resolved in the future eithe
by throwawaysec101 8y ago
Yes we should be hashing to avoid these sort of password logging issues. This is one of those old internet tech-debt that should be resolved in the future either via JS or HTML standard where password is hashed before sending to the server.
Reasons for this are:
- Internet services have grown and it's too much of a burden for user to have different password for every service.
- Even if users have different password, they use the same pattern and add some number of special character at the end which defeats the purpose if password pattern is revealed.
In order to protect the pattern of password across multiple services these login services should use client-side hashing. Think of it like something along the lines of SSL green icon in chrome, services not using client-side hashing are leaking it somewhere (no way to tell if they are not leaking).