Hacker News new | ask | show | jobs
by curyous 1244 days ago
If I understand correctly, the problem is that the hash created on the client side is used to create the encryption key before the server side hashes are applied. Only the master password uses the extra server side hashes.