First round of hashing could be done client-side, and then send that to the server.
Would be cool to also add salt so that the hash couldn’t get re-used across services even with the same source password/file if somehow captured.
Idea:
Enter username
Server sends salt to client
Enter password or key file
Client computes hash of the password or file with salt added (I have no idea how it’s used. If appended, some hashing functions could truncate the data, losing the salt. If prepended along with truncation, you just made the password even shorter. XOR?)
Client sends hash to server
Server hashes the hash same way as if it was password
If it matches, you’re in
Basically, the hash is your password. Data can be whatever.
Most websites already use JavaScript, so why not.
First round of hashing could be done client-side, and then send that to the server.
Would be cool to also add salt so that the hash couldn’t get re-used across services even with the same source password/file if somehow captured.
Idea:
Basically, the hash is your password. Data can be whatever.
Most websites already use JavaScript, so why not.