|
|
|
|
|
by d-z-m
884 days ago
|
|
can you elaborate on this? Or link something that does? My intuition is that whatever gets sent over the wire is effectively the password. Not sure how the server could validate some rolling hash of the password (based on like a timestamp or something) without having to store the pre-image(i.e. the raw password). |
|
https://www.rfc-editor.org/rfc/rfc2945
https://security.stackexchange.com/questions/18461/how-secur...