• u/lukmly013 💾 (lemmy.sdf.org)OP
    link
    fedilink
    arrow-up
    2
    ·
    2 hours ago

    First round of hashing could be done client-side, and then send that to the server.
    Would be cool to also add salt so that the hash couldn’t get re-used across services even with the same source password/file if somehow captured.

    Idea:

    1. Enter username
    2. Server sends salt to client
    3. Enter password or key file
    4. Client computes hash of the password or file with salt added (I have no idea how it’s used. If appended, some hashing functions could truncate the data, losing the salt. If prepended along with truncation, you just made the password even shorter. XOR?)
    5. Client sends hash to server
    6. Server hashes the hash same way as if it was password
    7. If it matches, you’re in

    Basically, the hash is your password. Data can be whatever.
    Most websites already use JavaScript, so why not.