Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm on my second glass of wine right now, and Erin is glaring at me, but help me understand how the server avoids needing the password plaintext at every login to figure out what the challenge-response needs to be?


You can store a hash of the password in the DB as opposed to the password itself. The only time the actual plaintext password needs to be passed is at registration time, and even then you could add another hash step to get rid of that. What you can't get rid of is having to transmit something that is equivalent to the password at registration time, but you can at login time. The nonce (and a transaction id) let you construct a system that isn't susceptible to replay attacks.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: