Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I.E., cram-md5 and related password schemes. It's a shame it fell out of favour, I'd sure prefer something like this over sending plain text passwords via TLS…


Ideally we eventually get rid of passwords and use secret/private keypairs in the browser, or have some browser-based SRP.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: