6 ms·
Client-side hashing of passwords does not provide any of the benefits of server-side password hashing, as the client-side hash of the password effectively becom
by donaltroddyn 7y ago
Client-side hashing of passwords does not provide any of the benefits of server-side password hashing, as the client-side hash of the password effectively becomes the password, as it's all that's required to authenticate.
Client-side hashing does provide very limited protection against plaintext reuse (on other sites where the user uses the same password) in the case that it's leaked in transit, which is far less of a concern now that HTTPS is cheap and widespread.
- colejohnson66 7y agoWhat about double hashing? Once on the client and once more on the server? Then, the server never sees the password, but prevents using a leaked password hash from the DB
- concert-gilled 7y agoI don't think that solves the problem. Instead of logging the plaintext passwords they would have just logged the 1-hashed password.
- txcwpalpha 7y agoThe problem with client-side hashing is that the client-hashed password then becomes the password. An attacker doesn't care if the password being sent to the server is "password123" or if it's "e2389cbb675c3ef00879482bd1702f76", because either way, all the attacker needs to do to log in as you is send that "e2389cbb..." string to the server. I suppose double hashing would have the benefit of preventing your server from ever seeing the plaintext password, but I'm don't think I've ever seen that be a major concern.