• u/lukmly013 💾 (lemmy.sdf.org)@lemmy.sdf.orgOP
    link
    fedilink
    arrow-up
    2
    arrow-down
    1
    ·
    20 hours ago

    If there would be an advantage to doing so, the server could still do that anyway. You’d just end up storing client salt and server salt.
    My main concern was MITM which doesn’t modify the webpage if web UI is used, such as on corporate networks which require client devices to have that network’s root certificate for scanning and activity logging.

    • Orygin@sh.itjust.works
      link
      fedilink
      arrow-up
      2
      ·
      14 hours ago

      The client salt would need to be consistent and “public” since the client needs it before login. It’s basically useless.