Hacker News new | ask | show | jobs
by grandpoobah 5205 days ago
Wouldn't npm client be sending the hashed version of the password rather than the password itself? then the server only has to compare the two hashes.