4 ms·
Yes i know. I think the excuses like "many sites dont do this" or "its up to the users to secure passwords" are just that---excuses for poor security practices
by theonewolf 14y ago
Yes i know.
I think the excuses like "many sites dont do this" or "its up to the users to secure passwords" are just that---excuses for poor security practices.
- adbachman 14y agoHashing on the client-side wouldn't make a difference if a MITM already has control of the SSL connection. They could just spoof the login form, swap out HackerRank's hashing code, and take your password anyway. If you don't trust the connection don't trust any part of it. Especially not the code your browser is executing.