Hacker News new | ask | show | jobs
by Bromskloss 2968 days ago
Wouldn't it be better to never even send the password to the server, but instead performing a challenge-response procedure? Does HTTP have no such feature built in?