Hacker News new | ask | show | jobs
by stubish 3499 days ago
You are assuming a lack of salt when the client hashes the password.
1 comments

You are right, in this case he can use a salt for the hash - my second point is still valid though, but I guess that is fundamentally so if you want to use passwords
While there is no 100% secure system, we are working very very hard to make our system as much secure as possible.