5 ms·
Because you can enforce password policies without the password ever leaving the (untrusted) client in clear text. I.e. the server only sees the hash and still k
by fisf 2y ago
Because you can enforce password policies without the password ever leaving the (untrusted) client in clear text. I.e. the server only sees the hash and still knows it's dealing with a strong PW.
- cyberax 2y agoA client-side script can do that. What is the attack model? A client maliciously changing the client script to supply a weak password?