Mojira Archive
WEB-327

Yggdrasil Password Hashing

I've always wondered why the password in the Yggdrasil Authentication Scheme is passed raw, without hashing it. It's not secure, the password can be, in theory, tracked down.
Could a hash analogue (e.g. /authenticatehash) be created?

Invalid

Vitalij Mikhaylov

2016-04-15, 06:52 PM

2016-04-22, 02:31 PM

2016-04-15, 09:23 PM

0

3