Re: Client password hashing

2022-02-16 Thread Berenguer Blasi
Yeah that sounds great also imo. I'll move Bowen's comment to the ticket and we can continue there. Thx On 16/2/22 14:55, J. D. Jordan wrote: Can we have the discussion on the ticket? Thanks -Jeremiah On Feb 16, 2022, at 6:23 AM, Bowen Song wrote: To me this doesn't sound very useful. Her

Re: Client password hashing

2022-02-16 Thread J. D. Jordan
Can we have the discussion on the ticket? Thanks -Jeremiah > On Feb 16, 2022, at 6:23 AM, Bowen Song wrote: > > To me this doesn't sound very useful. Here's a few threat model I can think > of that may be related to this proposal, and why is this not addressing the > issues & what should be

Re: Client password hashing

2022-02-16 Thread Bowen Song
To me this doesn't sound very useful. Here's a few threat model I can think of that may be related to this proposal, and why is this not addressing the issues & what should be done instead. 1. passwords are send over network in plaintext allows passive packet sniffier to learn about the passwo