4 ms·
Correct me if i'm wrong here, but to do what you're saying they could/should do here we basically have three options... 1) Storing the password in plaintext. 2
by TimSchumann 12y ago
Correct me if i'm wrong here, but to do what you're saying they could/should do here we basically have three options...
1) Storing the password in plaintext.
2) Sending the password over the wire in plaintext.
3) Computing two hashes on the same system (presumably) via the same function, with a known relationship between their inputs.
I guess the fourth option is they have a securely stored hash of the password, but that still wouldn't allow them to compute the 2x hash server side so we're looking at another round trip and/or number three above.
Not confidence inspiring.
- ars 12y ago> Correct me if i'm wrong here Yes, you are wrong. > we basically have three options Or sending the plaintext password over the wire using SSL? You are aware that to use a hash the server needs the plain text password right? And not just them, every server needs this? You are acting like getting the plaintext password is something strange. It's not. You can send the password encrypted or not, it has nothing to do with the hash on the server. > but that still wouldn't allow them to compute the 2x hash As I have said already, they are not computing the 2x hash.