Hacker News new | ask | show | jobs
by netdog 5607 days ago
> Hash based challenge-response authentication does require the server to know the plain password.

Not true. Read up on HTTP Digest authentication. It's described in RFC2617.

1 comments

Oh please. That's 12 years old, it can't possible still apply.

</troll>