• Axolotl.cpp@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    21 hours ago

    I’d rather not make the client do anything like that, you cannot trust a client, EVER; what if some script kiddie tries to send the clear passwd by modifyng the request? Ofc it’s a very minor problem but still…

      • Orygin@sh.itjust.works
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        20 hours ago

        I wouldn’t send the salt to the client. Have it hash the password, then the server hashes that with the salt for comparison and storage.
        But that would mean you can’t verify the password complexity server side, which can be bad for certain accounts.

        • u/lukmly013 💾 (lemmy.sdf.org)@lemmy.sdf.orgOP
          link
          fedilink
          arrow-up
          2
          arrow-down
          1
          ·
          20 hours ago

          If there would be an advantage to doing so, the server could still do that anyway. You’d just end up storing client salt and server salt.
          My main concern was MITM which doesn’t modify the webpage if web UI is used, such as on corporate networks which require client devices to have that network’s root certificate for scanning and activity logging.

          • Orygin@sh.itjust.works
            link
            fedilink
            arrow-up
            2
            ·
            14 hours ago

            The client salt would need to be consistent and “public” since the client needs it before login. It’s basically useless.