Please forgive me as I haven’t coded anything in 15ish years but even when making shitty PHP message boards back in the day we would always hash and salt passwords. The server would never see a plain text version of your password.
HTTPS is nice but that doesn’t guarantee what the server is doing with my plain text password.
iamak@infosec.pub 1 year ago
Why not hash it client side?