Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
0 points
consp
8y ago
0 comments
Share
Man in the middle attacks fetching for plaintext passwords
-- edit: using a KDF would improve it even more.
undefined | Better HN
0 comments
default
newest
oldest
anonymouz
8y ago
If the client only sends the hash to the server, a MitM also only needs to capture the hash.
croon
8y ago
Sure, but if they've MITM:ed your trusted certs, aren't you already boned in so many ways?
j
/
k
navigate · click thread line to collapse