No it doesn't. You can perform the first pass of salted hashing on the client-side.
This should not harm security, but it can improve it if someone on the datapath is logging requests but does not alter them.
This should not harm security, but it can improve it if someone on the datapath is logging requests but does not alter them.
The only security benefit is that it offers a bit of support for those that are reusing passwords since it doesn't expose the plain text.
Not really. JavaScript crypto is fundamentally broken: an attacker, malicious server or disgruntled employee can replace server-side JavaScript and remove the client-side hashing at any time. This is, notably, why Firefox Accounts are completely and totally insecure (and hence why Sync is unsuitable for storing any private data at all).