4 ms·
They could store a strength measurement alongside the salt and hash.
by dbpatterson 14y ago
They could store a strength measurement alongside the salt and hash.
- deleted 14y ago[deleted]
- martinced 14y agoSo you mean that the strength measurement is send from the client to the server alongside with the hash+salted password? Password are hashed+salted on the client side right? They're not transmitting password "in the clear" to hash+salt them on the server side? (even on SSL I'd be worried about passwords travelling between client/Apple-severs seen the number of hacks trying to exploit SSL/TLS recently)
- izakage 14y agoIf passwords were hashed+salted client-side, an attacker could use the hash+salt in exactly the same way as they would a 'raw' password. So the answer is no; the strength measurement would be done on the server when the password is being hashed or verified.
- Joeri 14y agoThat's true only for the initial password creation. During verification you could send down two salts, the real salt and a session salt. You double-hash the password on the client with both salts, and the server hashes on the server with the session salt. The hash that gets sent over the wire cannot be used for replay attacks. I don't think it adds much security though. If you don't trust the channel to properly protect the transmitted password, it's not possible to build a trusted relationship with the server. You have to assume ssl works.