2 ms·
Only doing that won't help. You might as well be transmitting the password, since someone can just copy the hash and then it would be equivalent to having the p
by omra 14y ago
Only doing that won't help. You might as well be transmitting the password, since someone can just copy the hash and then it would be equivalent to having the password. (Also known as a Pass the Hash attack, http://en.wikipedia.org/wiki/Pass_the_hash http://en.wikipedia.org/wiki/Pass_the_hash).
- wisty 14y agoEach website could have a salt. The issue is, if it's not a secure connection, it's vulnerable to hijacks.