(no title)
Sir_Substance | 5 years ago
It might protect the password if the user is reusing it elsewhere, but it doesn't protect the account the password is securing during the intercepted transmission.
The MITM attacker can just replay the hash.
Sir_Substance | 5 years ago
It might protect the password if the user is reusing it elsewhere, but it doesn't protect the account the password is securing during the intercepted transmission.
The MITM attacker can just replay the hash.
nucleardog|5 years ago
Sir_Substance|5 years ago
withinboredom|5 years ago