I guess what I'm asking is this: can someone walk me through the attack scenario? I don't really get it.
I guess what I'm asking is this: can someone walk me through the attack scenario? I don't really get it.
1. Mallory enters Alice's username and a random password
2. Website sends back Alice's plaintext password to be checked client side
3. Mallory inspects network traffic and retrieves Alice's plaintext password
It's also bad if the hash is sent back; now Mallory can run all sorts of attacks on the hash itself without worrying about rate limits or any other protection the site operator could implement.
If that's the case I completely misunderstood what they meant by processing the password with JavaScript. What you've described is insane; I thought the critique was in regards to processing a password locally before sending it to the server (e.g. local hashing).
> I've even seen a website where the password is sent to the browser and the password checking happens in Javascript.
i.e. the server sends the (plaintext or hashed) password to the client, and the client verifies it locally.
Edit: the original commenter replied as a sibling to you: https://news.ycombinator.com/item?id=18382949
As I recall, it did send you the plaintext password too, of course.