4 ms·
I blame the French: http://bit.ly/hjxHZQ http://bit.ly/hjxHZQ
by gzak 15y ago
I blame the French: http://bit.ly/hjxHZQ http://bit.ly/hjxHZQ
- Tyr42 15y agoThis is terrible. Question, under that law, do you need to store plaintext passwords if you hash the passwords on the browser side, since you don't "collect" the actual password from the user, as it never leaves their computer?
- lurker19 15y agoUnless you have some sort of server-trusted hardware system running on the client, hashing on the client is equivalent to not hashing at all, since you cannot force a client to hash before sending a password guess.