3 ms·
Doesn't this imply the server knowing the plaintext password?
by daef 5y ago
Doesn't this imply the server knowing the plaintext password?
- a1369209993 5y agoYes. You could (probably should) add a additional password=PBKDF(real_password) if that's a problem (eg because of password reuse), but it's not a essential feature from a cryptographic perspective.