Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No. Everything you do on the client side you can also keep not doing at all.

You can imagine the salted and hashed password in your scheme to be "the password". Because the server will still know it, and could use it to log in somewhere else (it just has to skip the salt-and-hash step).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: