|
|
|
|
|
by fc417fc802
38 days ago
|
|
There are substantial differences between database access, snooping the logs, internal (no TLS) wiretap, and full MITM of the frontend. Hashing client side minimizes the risk of any blast radius exceeding the bounds of your own service. There's obviously no way to prevent an adversary who achieves full MITM from gradually harvesting credentials over time. The only solution there is to use keys instead of passwords. |
|
In your enumeration, what is breached for this to be meaningfully impactful for other services where customers might be reusing credentials?