3 ms·
Credential stuffing is a thing. So it’s pretty good if a compromised website just cannot leak your password. But as the other comment pointed out the current s
by almost 5y ago
Credential stuffing is a thing. So it’s pretty good if a compromised website just cannot leak your password.
But as the other comment pointed out the current situation with web form login is that password is sent to server so it wouldn’t be worse than the the status quo.
- gjsman-1000 5y agoI hope you are kidding. A compromised website that was well designed should not leak your password any more than a client-side hashing implementation. This is because the passwords are hashed in the database. Client-side hashing means that, yes, initially the website is not receiving plaintext passwords, but a few quick code edits to maybe add some logging JavaScript or disable the client-side hashing implementation will fix that. And credential stuffing? Client-side hashing does absolutely nothing to prevent credential stuffing other than that you may need a GPU to do a lot of hashes quickly. Client-side hashing doesn't make a server handle more or less authentication requests.
- masklinn 5y ago> A compromised website that was well designed Ah yes, "if nobody makes any mistake there's no problem", that's worked so well forever hasn't it? > Client-side hashing means that, yes, initially the website is not receiving plaintext passwords, but a few quick code edits to maybe add some logging JavaScript or disable the client-side hashing implementation will fix that. That makes quite literally no sense, did you miss the entire thing and go off with whatever? The request here is to make the browser's support for HTTP authentication better. The entire point is that there is no "quick code edit" without owning the entire browser at which point you're quite thoroughly owned anyway.
- garbagecoder 5y agoI don’t think he understands salts or really hashing at all and this is messing up the logic in his posts.
- garbagecoder 5y agoIf “should” were a word that meant what people thinks it means, we wouldn’t need security at all.