Y
Hacker News
new
|
ask
|
show
|
jobs
by
amaccuish
2787 days ago
and if said "compromised" server simply decides to not supply the js that hashes the password?
2 comments
naasking
2787 days ago
Thanks for saying it. Client-side scripting can't protect against a compromised server when the client scripts are provided by that same server.
link
the_clarence
2787 days ago
The answer is that it depends. We could be talking about protected js with SRI, signed updates with an electron client, a browser plugin or native hashing, a protocol similar to SSH that hashes the client pw, etc.
link