Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Even HTTP Digest didn't require the password to be stored in plain text

As I understand it, it would still be required to store something that, if leaked, would allow anyone to create valid authentication responses? "HA1" effectively becomes the password, in that leaking it is as bad as leaking the password.



Right, edited.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: