3 ms·
> If the client and server have an agreement on a hashing protocol, there’s no reason that the browser shouldn’t be able to hash as well and prevent the passwor
by lixtra 5y ago
> If the client and server have an agreement on a hashing protocol, there’s no reason that the browser shouldn’t be able to hash as well and prevent the password from ever leaving memory on the client system.
Shouldn’t it be a proper challenge/response? Otherwise the hash is barely better than the password.