4 ms·
I think in that particular section he is referring to the possibility of allowing to client to validate the hash, which would be bad because it opens up the pos
by mcao 15y ago
I think in that particular section he is referring to the possibility of allowing to client to validate the hash, which would be bad because it opens up the possibility of brute forcing. I don't think he means you shouldn't use bcrypt on the server side.