Ask HN: Client-side MD5 password hashing
Now on the server, I treat the MD5 hash as if it's a regular password - but this is assuming that the treatment is consistent between sign-up and log-in. The advantage here is that nobody except your client knows what your plaintext password is.
I'm sure that people would've tried doing this before. Is there any disadvantage of doing this? I don't see any apart from the fact that disabling javascript will disable the login. Any advice about this would be very useful.