Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The difference is that I can verify the code, and the data send. If I send the password to serverside hashing, I can only trust the server to handle it correctly. Security wise that is a fairly important difference.


Are you saying you not only know of some website that does password hashing client-side but that you also inspect the javascript that site serves you every time you login?


Security wise there is a difference. This difference don't matter to the average person. I don't reuse passwords, so I don't need this protection.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: