|
|
|
|
|
by bradleyjg
4421 days ago
|
|
It's not at all common or best practices to run an expensive key derivation function browser side. Doing so adds little to no additional security -- if you don't trust the TLS channel then you are screwed any way you look at it. |
|