Has anyone tried a password auth system that standardizes on some front-end hashing strategy, so that the API never sees/touches the plain text version of the password?
3
1
9
Replying to @bcomnes
It's one of the oldest tricks in the books πŸ™ƒ

Dec 11, 2020 Β· 5:16 AM UTC

1
Replying to @aaronpk
I know bcrypt/hash+salt on server for storage has been best practice for ages. Or has client/browser side hashing before sending to a server been wide spread?
1
1
It's part of the old-school HTTP Digest Auth en.wikipedia.org/wiki/Digest… It just doesn't really solve things the way you'd expect.
1