Hacker News new | ask | show | jobs
by tajen 2966 days ago
If you don’t have control on the client, it’s a bad idea: Your suggestion means the password would be the hash itself, and it wouldn’t be necessary for an attacker to know the password.