4 ms·
Better handling how exactly? Either you send a login token over the wire in plain text, or you send it over HTTPS. It makes no difference if you hash client sid
by coderholic 14y ago
Better handling how exactly? Either you send a login token over the wire in plain text, or you send it over HTTPS. It makes no difference if you hash client side or not, as it's still a login token that can be sniffed and reused.
Even sniffing is only really likely to be a problem if you're on a public wifi network.
It seems like you're blowing this out of all proportion. It was only relatively recently that Facebook starting forcing HTTPS for authentication, and many many sites (inc. HN) still don't.
- paulgb 14y agoI think the point is that if the password is one that's used elsewhere, if it's client-side encrypted, at least it can't be captured for use on another site by an eavesdropper. It does nothing against an attacker who can get in the middle of the transmission though.