3 ms·
After reading the comments I have an idea. I'm sure someone thought of it already though. If the password is p and the hash function is H(), server stores the h
by httpz 8y ago
After reading the comments I have an idea. I'm sure someone thought of it already though.
If the password is p and the hash function is H(), server stores the hashed password H(p).
When the login screen loads, server sends the server time so with reasonably fast internet, the client can estimate the server time. Let's call the estimated current server time t. On login, client sends H(H(p)+t) with t. Now the server can compute H(H(p)+t) with the t from the client and verify if the hash match and also check if t is within few seconds of the current server time.
This way if any data that goes over the network leaks for gets logged, it'll only be valid for few seconds. Also salting before hashing should go somewhere in there but it'll make it a bit more complicated.