Comment on Passwords sent as plaintext?
clemdawg@lemmy.world 1 year agoPlease forgive me as I haven’t coded anything in 15ish years but even when making shitty PHP message boards back in the day we would always hash and salt passwords. The server would never see a plain text version of your password.
HTTPS is nice but that doesn’t guarantee what the server is doing with my plain text password.
clb92@kbin.social 1 year ago
As you realized in your edit already, this part is not correct. The server would always receive your password plaintext (when signing up and when logging in), but only store it hashed and salted.