Alex Rivera | Logout

Should I hash the password before sending it to the server side?

Asked 2010-08-02T19:52:00.333
167

I noticed that most sites send the passwords as plain text over HTTPS to the server. Is there any advantage if instead of that I sent the hash of the password to the server? Would it be more secure?

Edit
Report

1 Answer

15

Sending a hash over the wire completely defeats the purpose of the hash, because an attacker can simply send the hash and forget about the password. In a nutshell, a system that athenticates using a hash in clear text is wide open and can be compromise with nothing more than network sniffing.

answered 2010-08-02T20:07:56.640

Your Answer