clb92
@clb92@kbin.social
This is a remote user, information on this page may be incomplete. View at Source ↗
- Comment on Passwords sent as plaintext? 1 year ago:
The server would never see a plain text version of your password.
As you realized in your edit already, this part is not correct. The server would always receive your password plaintext (when signing up and when logging in), but only store it hashed and salted.
- Comment on Passwords sent as plaintext? 1 year ago:
The server needs to receive your password to verify it and log you it. That's how it always is. As long as you are connecting via HTTPS, this is not a problem.